CVE-2026-85434
nicheUnauthenticated node ping spoofing hijacks bridge routes in MOOS-IvP uFldShoreBroker
MOOS-IvP's uFldShoreBroker through version 24.8.1 accepts NODE_BROKER_PING messages without verifying their authenticity (CWE-345: insufficient verification of data authenticity) before establishing outbound bridge routes. An attacker with network reachability to the broker can publish crafted NODE_BROKER_PING messages containing malicious HostRecord data, causing the broker to create routes that point at attacker-controlled addresses. This lets the attacker redirect bridged variables, enabling interception or manipulation of data exchanged between autonomous vehicles and shore systems, consistent with the high confidentiality and integrity impacts in the 9.3 CVSS 4.0 score. Affected operators are those running MOOS-IvP-based marine autonomy deployments that use the uFldShoreBroker shore-side bridging component. No exploitation has been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade uFldShoreBroker to a release newer than 24.8.1 once a patched version is published (no fixed version is specified in available disclosures); until then, restrict network access to the shore broker to trusted vehicles and operators. Filter NODE_BROKER_PING traffic from unauthenticated sources and avoid exposing the broker's bridging port to untrusted networks.
| MOOS-IvP (open-source project) uFldShoreBroker | all versions through 24.8.1 (no fixed version specified in available disclosures) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
- Weakness
- CWE-345
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.