{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amoos_ivpufldnodecomms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moos_ivp:ufldnodecomms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85429"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["uFldNodeComms (\u003c= 24.8.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MOOS-IvP"],"content_html":"\u003cp\u003eMOOS-IvP is an open-source software project for autonomy, widely used in robotic and marine research applications. The vulnerability, designated CVE-2026-85429, resides in the uFldNodeComms component, which manages communication between different nodes in the autonomy network. In affected versions through 24.8.1, the application fails to verify the authenticity of incoming NODE_MESSAGE packets. Instead of validating the identity against the actual connection source (e.g., verifying the IP address or socket origin), the software trusts the source node identity explicitly defined within the message body.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an attacker capable of communicating with the uFldNodeComms component to craft malicious NODE_MESSAGE packets. By populating the source identity field in the message payload with the name of a legitimate, trusted node, an attacker can impersonate that node. This allows for the injection of arbitrary variable notifications into the MOOS database, enabling unauthorized control, data corruption, or manipulation of the autonomy behaviors controlled by the MOOS-IvP system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the injection of unauthorized command or state information into the system's database. Given the nature of MOOS-IvP in robotic and autonomous system control, this can result in the subversion of mission-critical behaviors, leading to loss of control, erratic navigation, or data manipulation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of MOOS-IvP to a patched version beyond 24.8.1 once available to address the flawed identity validation logic.\u003c/li\u003e\n\u003cli\u003eImplement network-level segmentation to restrict access to the uFldNodeComms communication port to only known and trusted peer addresses, mitigating the impact of the identity spoofing vulnerability.\u003c/li\u003e\n\u003cli\u003eInspect firewall logs or network monitoring tools for unauthorized traffic attempting to reach the port utilized by uFldNodeComms from unexpected source IPs.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T23:25:57Z","date_published":"2026-09-03T23:25:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-spoofing/","summary":"The uFldNodeComms component in MOOS-IvP versions up to 24.8.1 fails to validate node identity, allowing attackers to spoof packets and inject arbitrary variable notifications.","title":"Identity Spoofing Vulnerability in MOOS-IvP uFldNodeComms","url":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-spoofing/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:moos_ivp:ufldnodecomms:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}