<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Core-Moos (&lt;= 10.4.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/core-moos--10.4.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 23:29:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/core-moos--10.4.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Buffer Over-Read Vulnerability in MOOS core-moos</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85455/</link><pubDate>Thu, 03 Sep 2026 23:29:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85455/</guid><description>A buffer over-read vulnerability in CMOOSCommPkt allows an unauthenticated remote attacker to trigger out-of-bounds memory access via a crafted four-byte TCP packet.</description><content:encoded><![CDATA[<p>MOOS core-moos, an open-source project used in autonomous vehicle and robotics research, contains a critical buffer over-read vulnerability in the CMOOSCommPkt component affecting versions through 10.4.0. The flaw resides in the handling of four-byte network packets during the deserialization process. An unauthenticated attacker can exploit this vulnerability by establishing a TCP connection to the MOOSDB service port and transmitting a specifically crafted packet. This interaction triggers an out-of-bounds memory access, which may allow the attacker to read sensitive process memory. This vulnerability is significant for environments deploying MOOS-based systems in networked research or industrial control environments, as it allows for unauthorized data access without requiring prior authentication or valid credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthenticated remote attacker to disclose sensitive information from the memory of the MOOSDB process. This could potentially lead to the exposure of credentials, session tokens, or other private data residing in memory. Given the role of core-moos in autonomous system middleware, the impact is high for researchers and engineers who rely on the platform for mission-critical or sensitive robotics deployments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade core-moos installations to a version released after 10.4.0 that contains the patch for CVE-2026-85455.</li>
<li>Until patching is possible, implement network-level access control lists (ACLs) to restrict access to the MOOSDB TCP port to only known, trusted controller IP addresses.</li>
<li>Monitor network traffic logs for connections to the standard MOOSDB port that do not originate from authorized components or management stations.</li>
<li>Deploy ingress filtering to block unexpected TCP traffic directed at MOOS-enabled endpoints to limit the attack surface.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item><item><title>CVE-2026-85440: Heap Overflow in MOOS core-moos</title><link>https://feed.craftedsignal.io/briefs/2026-09-moos-heap-overflow/</link><pubDate>Thu, 03 Sep 2026 23:25:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-moos-heap-overflow/</guid><description>A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.</description><content:encoded><![CDATA[<p>MOOS core-moos versions up to 10.4.0 contain a critical heap-based buffer overflow vulnerability within the MOOSCommPkt packet handling logic. The issue resides in the HandShake phase, which occurs before authentication is established. An unauthenticated remote attacker can supply a negative value in the packet length field, which bypasses existing signed integer checks within the InflateTo() function. This discrepancy leads to an improper size conversion when the data is passed to the recv() function, causing a heap overflow of a four-byte buffer. Successful exploitation allows an attacker to write arbitrary data into the process memory, potentially leading to remote code execution or application crashes. Given the pre-authentication nature of this flaw, defenders should prioritize patching or restricting access to the MOOS communication ports.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes a TCP/IP connection to the target host on the MOOS communication port.</li>
<li>Attacker initiates the HandShake phase of the communication protocol.</li>
<li>Attacker crafts a malicious packet header containing a negative integer in the packet length field.</li>
<li>The victim application receives the malicious packet via the InflateTo() function.</li>
<li>The vulnerability in the signed integer check allows the negative length to pass validation.</li>
<li>The application performs a heap-based memory allocation based on the unchecked length.</li>
<li>The recv() function processes the attacker-supplied data, resulting in a heap overflow of the internal four-byte buffer.</li>
<li>Attacker achieves arbitrary memory write, leading to remote code execution or process termination.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary code or cause a denial-of-service condition on affected MOOS installations. This affects systems utilizing MOOS core-moos versions 10.4.0 and earlier. Organizations relying on this software for underwater vehicle communication or similar robotics research environments are at high risk if instances are exposed to untrusted networks.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions:</p>
<ul>
<li>Patch core-moos by upgrading to a version exceeding 10.4.0 immediately upon release of vendor updates.</li>
<li>Until patching is possible, restrict access to MOOS communication ports via host-based firewalls or network access control lists to known trusted endpoints only.</li>
<li>Monitor network traffic for anomalous packet headers directed toward MOOS services, specifically looking for TCP streams containing negative length identifiers in the handshake phase.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve</category><category>authentication-bypass</category><category>middleware</category><category>denial-of-service</category><category>network-vulnerability</category><category>vulnerability</category><category>network-security</category><category>remote-access</category></item><item><title>Authentication Bypass in MOOSDB HTTP Server</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85428/</link><pubDate>Thu, 03 Sep 2026 23:24:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85428/</guid><description>The MOOSDB HTTP server in core-moos versions 10.4.0 and earlier contains an authentication bypass vulnerability allowing unauthenticated remote attackers to modify MOOS variables via crafted HTTP requests.</description><content:encoded><![CDATA[<p>MOOS core-moos versions up to and including 10.4.0 contain a critical authentication bypass vulnerability within the optional MOOSDB HTTP server component. This service, which facilitates inter-process communication in autonomy-oriented systems, fails to enforce authentication checks for administrative requests. Consequently, unauthenticated remote attackers can send specially crafted HTTP requests to the MOOSDB service port to write, modify, or inject MOOS variables. This vulnerability is particularly severe because it allows for the unauthorized manipulation of system states, including the modification of actuator commands and override parameters. Successful exploitation grants attackers direct control over operational variables, potentially leading to the compromise of system integrity and safety in environments utilizing core-moos for autonomous decision-making.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 9.8. Exploitation could allow attackers to gain unauthorized control over system operations by injecting or modifying MOOS variables. This poses a significant risk to systems in marine robotics, autonomous vehicle research, and other sectors relying on core-moos, where unauthorized actuator changes could lead to loss of control, physical damage, or mission failure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade core-moos to the latest patched version when available to remediate CVE-2026-85428.</li>
<li>Implement network-level segmentation to restrict access to the MOOSDB HTTP server port (default 9000-9005 range) to authorized management IPs only.</li>
<li>Audit network traffic for unauthorized HTTP traffic directed at the MOOSDB service port.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>