{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amoos_ivppmarineviewer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moos_ivp:pmarineviewer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85449"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pMarineViewer (\u003c= 24.8.1)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","denial-of-service","marine-systems"],"_cs_type":"advisory","_cs_vendors":["MOOS-IvP"],"content_html":"\u003cp\u003eMOOS-IvP pMarineViewer, an application typically used for marine autonomy and visualization, contains a vulnerability in how it handles NODE_REPORT messages. The application fails to enforce limits on the number of tracked node identities processed by the system. An attacker with access to the MOOS publish/subscribe communication bus can inject a large volume of crafted NODE_REPORT messages, each containing a unique node name. This action forces the application to allocate memory for every distinct identity reported. Continued injection leads to significant memory exhaustion, eventually causing the operator display to stall or crash. This issue is particularly critical in systems where pMarineViewer is used for mission-critical situational awareness. The vulnerability affects all versions up to and including 24.8.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition for the pMarineViewer operator display. In the context of marine robotic missions, this prevents operators from receiving real-time situational awareness, potentially leading to the loss of control or monitoring of autonomous assets. The vulnerability is unauthenticated and impacts the core visualization utility of the MOOS-IvP software suite.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInventory systems running MOOS-IvP and identify instances of pMarineViewer version 24.8.1 or earlier.\u003c/li\u003e\n\u003cli\u003eImplement network-level or middleware access controls to restrict access to the MOOS publish/subscribe communication bus, preventing unauthorized entities from injecting arbitrary NODE_REPORT messages.\u003c/li\u003e\n\u003cli\u003ePrioritize the deployment of updates provided by the MOOS-IvP maintainers that implement validation and limiting logic on node identity tracking.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T23:29:10Z","date_published":"2026-09-03T23:29:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-memory-exhaustion/","summary":"An unauthenticated memory exhaustion vulnerability in MOOS-IvP pMarineViewer (\u003c= 24.8.1) allows attackers to stall the operator display by flooding the application with unbounded NODE_REPORT messages.","title":"Memory Exhaustion Vulnerability in MOOS-IvP pMarineViewer","url":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-memory-exhaustion/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:moos_ivp:pmarineviewer:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}