{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/moos-ivp--24.8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moos_ivp:moos_ivp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85437"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MOOS-IvP (\u003c= 24.8.1)","MOOS-IvP (through 24.8.1)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cve","rce","memory-corruption","buffer-overflow","research-robotics","cve-2026-85438","remote-code-execution","command-injection","denial-of-service","middleware","maritime"],"_cs_type":"advisory","_cs_vendors":["MOOS-IvP"],"content_html":"\u003cp\u003eMOOS-IvP through version 24.8.1 contains multiple buffer overflow vulnerabilities located within its IvP function string decoders. The vulnerability arises due to the application's failure to adequately validate length fields provided in attacker-controlled input. By crafting malicious encoded strings where the declared field length differs significantly from the actual field length, an attacker can induce heap or stack buffer overflows. These memory corruption events can be leveraged to achieve arbitrary remote code execution. The vulnerability is triggered when the affected components process malicious MOOS variables or malformed alog files, which are central to the MOOS-IvP communication and logging architecture. Defenders should prioritize patching, as these vulnerabilities are classified with a CVSS v3.1 base score of 9.8, indicating high potential for exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker to execute arbitrary code with the privileges of the MOOS-IvP process. In many deployments, these processes operate within critical autonomous systems or research environments. If exploited, an attacker could gain persistent access, exfiltrate sensitive mission data, or disrupt the operation of underwater autonomous vehicles and other marine robotic systems using the MOOS-IvP framework.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of MOOS-IvP to version 24.8.2 or later to address the vulnerable IvP function string decoders identified in CVE-2026-85437.\u003c/li\u003e\n\u003cli\u003eAudit all external inputs feeding into MOOS variables and restrict access to alog files to trusted administrative users only.\u003c/li\u003e\n\u003cli\u003eMonitor process integrity for abnormal crashes or memory access violations that might indicate attempted exploitation of these buffer overflows.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T23:28:48Z","date_published":"2026-09-03T23:25:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-buffer-overflow/","summary":"Multiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.","title":"Buffer Overflow Vulnerabilities in MOOS-IvP","url":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - MOOS-IvP (\u003c= 24.8.1)","version":"https://jsonfeed.org/version/1.1"}