ZeroHour

CVE-2026-85431

niche

Unauthenticated UDP Packet Injection in MOOS essential-moos pMOOSBridge

CVSS 4.0
8.7 high
EPSS
2%p78
Published
()
Modified
AI analysis

MOOS essential-moos through version 10.0.1 is vulnerable to unauthenticated UDP packet injection in the pMOOSBridge component when it is configured with UDPListen enabled. An attacker who can reach the configured UDP port can send crafted datagrams that the bridge accepts without verifying their authenticity, injecting arbitrary variables into the local MOOS community while spoofing the source and community identifiers. Because MOOS variables feed robot control and mission logic, forged variables can change the behavior or decisions of a running MOOS-based system, though the flaw does not by itself expose data or disrupt availability (integrity impact only per the CVSS 4.0 score of 8.7). Only deployments running pMOOSBridge with UDPListen are affected, and exploitability depends on whether that UDP port is reachable from an untrusted network, which is uncommon in typical isolated robotics/research deployments. No public proof-of-concept or confirmed exploitation is known; the issue is not in CISA's KEV and EPSS assigns a 1.9% probability of exploitation within 30 days.

What to do: Upgrade essential-moos to a release newer than 10.0.1 once a patched version is available. As an interim mitigation, disable UDPListen in pMOOSBridge or restrict the configured UDP port with firewall rules so only trusted hosts can send packets to it. Operators should audit running configurations for UDPListen and monitor the MOOS community for unexpected or spoofed source variables.

Affected
MOOS Project (essential-moos) Essential MOOS, pMOOSBridge component (when configured with UDPListen)all versions through and including 10.0.1
Estimated exposure
nicheNo basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers.

Weakness
CWE-345
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.