{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amoos-ivpufldshorebroker/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moos-ivp:ufldshorebroker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-85434"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["uFldShoreBroker (\u003c= 24.8.1)"],"_cs_severities":["critical"],"_cs_tags":["denial-of-service","vulnerability","robotics"],"_cs_type":"advisory","_cs_vendors":["MOOS-IvP"],"content_html":"\u003cp\u003eMOOS-IvP uFldShoreBroker, a component used for coordinating data bridging in autonomous marine vehicle simulations and control systems, contains a critical security vulnerability (CVE-2026-85434). The flaw exists because the software fails to authenticate 'NODE_BROKER_PING' messages before processing them to establish outbound bridge routes. By publishing a crafted 'NODE_BROKER_PING' message containing malicious 'HostRecord' data, an attacker can coerce the broker into redirecting variable traffic to arbitrary attacker-controlled IP addresses. This effectively allows an adversary to intercept, modify, or drop sensitive operational data flowing across the bridge, potentially impacting the mission integrity of connected autonomous nodes. This vulnerability affects all versions of uFldShoreBroker up to and including 24.8.1. Defenders must identify any instances of this software within their network segments and restrict message publication access to authorized nodes only.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the redirection of sensitive telemetry and control variables to malicious infrastructure. In maritime autonomous systems, this can lead to operational disruption, loss of communication with remote vessels, or the injection of false navigational or control data, potentially causing physical damage or loss of autonomous assets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade uFldShoreBroker to a patched version beyond 24.8.1 immediately upon vendor availability.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation for systems running MOOS-IvP to limit the exposure of the messaging bus to unauthorized participants.\u003c/li\u003e\n\u003cli\u003eAudit and restrict permissions for publishing 'NODE_BROKER_PING' messages to known, authenticated, and trusted sources within the MOOS-IvP network.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for unexpected outbound connections from nodes running uFldShoreBroker to unknown or non-standard external destinations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T23:29:04Z","date_published":"2026-09-03T23:24:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-vulnerability/","summary":"MOOS-IvP uFldShoreBroker through version 24.8.1 is vulnerable to unauthorized route manipulation via forged node ping messages, enabling attackers to redirect data to arbitrary network locations.","title":"Unauthenticated Bridge Redirection in MOOS-IvP uFldShoreBroker","url":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:moos-Ivp:ufldshorebroker:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}