ZeroHour

CVE-2026-85449

niche

Unauthenticated memory-exhaustion DoS in MOOS-IvP pMarineViewer

CVSS 4.0
8.7 high
EPSS
<1%p33
Published
()
Modified
AI analysis

MOOS-IvP pMarineViewer, the operator display for the open-source MOOS-IvP marine-robotics autonomy suite, does not cap the number of node identities it tracks from NODE_REPORT messages (CWE-770), so unbounded distinct node names accumulate in memory. An attacker with network reachability to the MOOS community can publish crafted NODE_REPORT data without authentication, causing unbounded memory growth. The outcome is memory exhaustion that stalls the operator display (high availability impact); confidentiality and integrity are not affected. All deployments of pMarineViewer up to and including version 24.8.1 are affected, primarily academic, naval, and research marine-robotics teams. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only a ~0.4% probability of exploitation within 30 days.

What to do: Upgrade MOOS-IvP/pMarineViewer to a release newer than 24.8.1 once a patched build is published, since no fixed version is specified in the advisory data. Until then, restrict network access to the MOOS community and viewer connections to trusted subnets or authenticated operators, and monitor the viewer process for abnormal memory growth, restarting it if the display stalls.

Affected
MOOS-IvP (open-source project) pMarineViewerall versions through and including 24.8.1
Estimated exposure
nichelikely low hundreds to low thousands of research/lab deployments; no public install counts (unknown precisely) — MOOS-IvP is a niche open-source autonomy middleware concentrated in academic and naval marine-robotics laboratories with no published active-install or internet-exposure counts, so this is a deployment-pattern estimate, not a measured…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REPORT data to cause memory exhaustion and stall the operator display without authentication.

Weakness
CWE-770
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.