Skip to content
Threat Feed

Vendor

MOOS-IvP

9 briefs RSS
low advisory

Memory Exhaustion Vulnerability in MOOS-IvP pMarineViewer

An unauthenticated memory exhaustion vulnerability in MOOS-IvP pMarineViewer (<= 24.8.1) allows attackers to stall the operator display by flooding the application with unbounded NODE_REPORT messages.

pMarineViewer vulnerability denial-of-service marine-systems
1t 1c
medium threat

Resource Exhaustion in MOOS-IvP pRealm via REALMCAST_REQ

MOOS-IvP pRealm version 24.8.1 and earlier is vulnerable to a denial-of-service attack due to improper validation of REALMCAST_REQ subscriptions, allowing attackers to exhaust system resources.

exploited pRealm
1t 1c
high advisory

Identity Spoofing Vulnerability in MOOS-IvP uFldNodeComms

The uFldNodeComms component in MOOS-IvP versions up to 24.8.1 fails to validate node identity, allowing attackers to spoof packets and inject arbitrary variable notifications.

uFldNodeComms
1c
critical advisory

CVE-2026-85440: Heap Overflow in MOOS core-moos

A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.

core-moos cve authentication-bypass middleware denial-of-service network-vulnerability vulnerability network-security remote-access
5t 1c
critical advisory

Buffer Overflow Vulnerabilities in MOOS-IvP

Multiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.

MOOS-IvP +1 vulnerability cve rce memory-corruption buffer-overflow research-robotics cve-2026-85438 remote-code-execution +4
4t 1c
critical advisory

Unauthenticated Bridge Redirection in MOOS-IvP uFldShoreBroker

MOOS-IvP uFldShoreBroker through version 24.8.1 is vulnerable to unauthorized route manipulation via forged node ping messages, enabling attackers to redirect data to arbitrary network locations.

uFldShoreBroker denial-of-service vulnerability robotics
1t 1c
critical advisory

Authentication Bypass and Message Injection in MOOS pShare

The pShare component in MOOS essential-moos versions up to 10.0.1 is vulnerable to unauthenticated UDP message injection and denial-of-service.

essential-moos vulnerability remote-code-execution network-security cve authorization-bypass robotics
2t 1c
high advisory

Command Injection in MOOS-IvP uMemWatch

MOOS-IvP uMemWatch through version 24.8.1 is vulnerable to command injection due to improper sanitization of MOOS client names, allowing arbitrary code execution.

uMemWatch
1t 1c
critical advisory

Remote Code Execution in MOOS-IvP iSay

The iSay component in MOOS-IvP through 24.8.1 is vulnerable to remote code execution because it passes unsanitized SAY_MOOS variable content directly to a shell, allowing command injection via backticks or substitution syntax.

iSay
1r 1t 1c