CVE-2026-85435
nicheMessage Source Spoofing in MOOS-IvP uFldNodeBroker Exposes Vehicle Telemetry
uFldNodeBroker in the open-source MOOS-IvP autonomy suite (through and including 24.8.1) does not verify the authenticity of TRY_SHORE_HOST messages on the vehicle bus, an instance of CWE-345 (insufficient verification of data authenticity). An attacker who can publish on the vehicle network sends a forged TRY_SHORE_HOST message, causing the broker to enroll an attacker-controlled shore route. The broker then bridges vehicle traffic to the attacker, who receives sensor data and control information and can impersonate the legitimate shore link; availability of the vehicle itself is not directly impacted. Affected users are operators of unmanned surface/underwater vehicles running MOOS-IvP's uFldNodeBroker, typically academic, naval, and government research fleets. No public proof-of-concept or in-the-wild exploitation is known; it is not in CISA KEV and EPSS assigns a 0.2% probability of exploitation in the next 30 days.
What to do: Until a patched release beyond 24.8.1 is published, isolate uFldNodeBroker's vehicle bus from untrusted networks and restrict which nodes may publish TRY_SHORE_HOST messages. Review broker logs and enrolled shore hosts for unknown or unexpected endpoints receiving bridged traffic, and upgrade promptly when the vendor ships a fixed version.
| MOOS-IvP (open-source project) uFldNodeBroker | all versions up to and including 24.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
- Weakness
- CWE-345
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.