ZeroHour

CVE-2026-85451

niche

Hard-coded passphrase allows remote process termination in MOOS core-moos

CVSS 4.0
7.1 high
EPSS
<1%p13
Published
()
Modified
AI analysis

MOOS core-moos through 10.4.0 relies on a hard-coded passphrase to authorize multicast shutdown commands handled by its SuicidalSleeper component (CWE-798, use of hard-coded credentials). Because the default MOOS multicast group and port are used, any peer reachable on the adjacent network segment can join the group, enumerate running MOOS processes, and issue authorized termination commands. An attacker gains the ability to remotely shut down individual MOOS processes or an entire MOOS community, producing high availability impact (denial of service) with only limited confidentiality loss through process enumeration. Anyone running MOOS core-moos up to and including 10.4.0 with default multicast settings — typically robotics and marine-autonomy deployments — is affected. No exploitation is known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates a 0.2% probability of exploitation in the next 30 days.

What to do: Upgrade to a core-moos release newer than 10.4.0 when a patched version becomes available, as the advisory does not specify a fixed version. Until then, restrict multicast reachability by firealling or segmenting the default MOOS multicast group and port, and disable or reconfigure the SuicidalSleeper component where it is not required. Audit running hosts for listeners on the default MOOS multicast group/port and check active MOOS missions for SuicidalSleeper usage.

Affected
MOOS project (open-source) core-moos (MOOS core)all versions through 10.4.0 (10.4.0 and earlier)
Estimated exposure
nichelikely hundreds to low-thousands of deployments (estimate; no public install counts) — MOOS is niche open-source robotics middleware used mainly in academic and marine-autonomy research (e.g., MOOS-IvP-based autonomy stacks), with no public install counts, so the order of magnitude reflects its small, research-oriented user…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.

Weakness
CWE-798
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.