{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aoxford_universitycore-moos/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:oxford_university:core-moos:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-85455"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["core-moos (\u003c= 10.4.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Oxford University"],"content_html":"\u003cp\u003eMOOS core-moos, an open-source project used in autonomous vehicle and robotics research, contains a critical buffer over-read vulnerability in the CMOOSCommPkt component affecting versions through 10.4.0. The flaw resides in the handling of four-byte network packets during the deserialization process. An unauthenticated attacker can exploit this vulnerability by establishing a TCP connection to the MOOSDB service port and transmitting a specifically crafted packet. This interaction triggers an out-of-bounds memory access, which may allow the attacker to read sensitive process memory. This vulnerability is significant for environments deploying MOOS-based systems in networked research or industrial control environments, as it allows for unauthorized data access without requiring prior authentication or valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to disclose sensitive information from the memory of the MOOSDB process. This could potentially lead to the exposure of credentials, session tokens, or other private data residing in memory. Given the role of core-moos in autonomous system middleware, the impact is high for researchers and engineers who rely on the platform for mission-critical or sensitive robotics deployments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade core-moos installations to a version released after 10.4.0 that contains the patch for CVE-2026-85455.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, implement network-level access control lists (ACLs) to restrict access to the MOOSDB TCP port to only known, trusted controller IP addresses.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic logs for connections to the standard MOOSDB port that do not originate from authorized components or management stations.\u003c/li\u003e\n\u003cli\u003eDeploy ingress filtering to block unexpected TCP traffic directed at MOOS-enabled endpoints to limit the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T23:29:38Z","date_published":"2026-09-03T23:29:38Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85455/","summary":"A buffer over-read vulnerability in CMOOSCommPkt allows an unauthenticated remote attacker to trigger out-of-bounds memory access via a crafted four-byte TCP packet.","title":"Buffer Over-Read Vulnerability in MOOS core-moos","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85455/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:oxford_university:core-Moos:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}