<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:moos_ivp:pmarineviewer:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amoos_ivppmarineviewer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 23:29:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amoos_ivppmarineviewer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Memory Exhaustion Vulnerability in MOOS-IvP pMarineViewer</title><link>https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-memory-exhaustion/</link><pubDate>Thu, 03 Sep 2026 23:29:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-memory-exhaustion/</guid><description>An unauthenticated memory exhaustion vulnerability in MOOS-IvP pMarineViewer (&lt;= 24.8.1) allows attackers to stall the operator display by flooding the application with unbounded NODE_REPORT messages.</description><content:encoded><![CDATA[<p>MOOS-IvP pMarineViewer, an application typically used for marine autonomy and visualization, contains a vulnerability in how it handles NODE_REPORT messages. The application fails to enforce limits on the number of tracked node identities processed by the system. An attacker with access to the MOOS publish/subscribe communication bus can inject a large volume of crafted NODE_REPORT messages, each containing a unique node name. This action forces the application to allocate memory for every distinct identity reported. Continued injection leads to significant memory exhaustion, eventually causing the operator display to stall or crash. This issue is particularly critical in systems where pMarineViewer is used for mission-critical situational awareness. The vulnerability affects all versions up to and including 24.8.1.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a denial-of-service condition for the pMarineViewer operator display. In the context of marine robotic missions, this prevents operators from receiving real-time situational awareness, potentially leading to the loss of control or monitoring of autonomous assets. The vulnerability is unauthenticated and impacts the core visualization utility of the MOOS-IvP software suite.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Inventory systems running MOOS-IvP and identify instances of pMarineViewer version 24.8.1 or earlier.</li>
<li>Implement network-level or middleware access controls to restrict access to the MOOS publish/subscribe communication bus, preventing unauthorized entities from injecting arbitrary NODE_REPORT messages.</li>
<li>Prioritize the deployment of updates provided by the MOOS-IvP maintainers that implement validation and limiting logic on node identity tracking.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>vulnerability</category><category>denial-of-service</category><category>marine-systems</category></item></channel></rss>