ZeroHour

CVE-2026-85437

niche

Buffer Overflows in MOOS-IvP IvP String Decoders May Enable Remote Code Execution

CVSS 4.0
9.3 critical
EPSS
<1%p50
Published
()
Modified
AI analysis

MOOS-IvP through 24.8.1 is affected by multiple buffer overflow vulnerabilities (CWE-787, out-of-bounds write) in the IvP function string decoders, which accept attacker-controlled length fields without validating them. An attacker can trigger the flaw by sending crafted encoded strings whose declared field lengths do not match their actual lengths, delivered through MOOS variables or by feeding a crafted alog file to components that parse it. The resulting heap or stack buffer overflows could allow remote code execution with the privileges of the affected MOOS process, per the critical CVSS 4.0 score of 9.3. Anyone running MOOS-IvP up to and including version 24.8.1 — on autonomous vehicle stacks, shore-side ground stations, simulators, or alog post-processing tools — is potentially affected. No public proof-of-concept or confirmed exploitation is known, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.7% chance of exploitation within 30 days.

What to do: Upgrade MOOS-IvP to a release newer than 24.8.1 as soon as a patched version is published (no fixed version is specified in the available data). Until then, treat alog files from untrusted sources as suspect before parsing, and restrict network access to MOOSDB and other MOOS-IvP listeners so only trusted peers can inject MOOS variables. Audit autonomy stacks, shore-side tools, and any analysis software that parses alog files for vulnerable versions.

Affected
MOOS-IvP (open-source project) MOOS-IvP (IvP function string decoders)all versions through and including 24.8.1
Estimated exposure
nicheon the order of a few thousand robot, ground-station, and simulator instances — MOOS-IvP is an open-source marine-robotics autonomy middleware used primarily by academic labs, naval/defense autonomy programs, and robotics competition teams, implying a niche install base of thousands of deployments rather than mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.

Weakness
CWE-787
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.