Impact
The vulnerability allows any network client to connect to the MOOS database service without authentication, granting full publish, subscribe, and DB_CLEAR permissions; a malicious actor can reset all variables and clear email queues, effectively compromising the integrity and availability of the system.
Affected Systems
The flaw affects The MOOS core‑moos version 10.4.0 and earlier; the issue resides in the MOOSDB wire protocol implementation within the core‑moos code base.
Risk and Exploitability
With a CVSS score of 9.3 the exploit offers a high severity risk; although EPSS data is not available, the absence of KEV listing does not negate the possibility of active exploitation. The likely attack vector is a remote network connection to the MOOSDB service, where an unauthenticated client can assume any client identity by bypassing the compile‑time protocol string check.
OpenCVE Enrichment