Impact
MOOS‑IvP delivers a command to the operating system shell through the SAY_MOOS variable handler without proper sanitization. Attackers can publish SAY_MOOS messages that contain backticks or command substitution syntax, causing the iSay process to execute arbitrary shell commands. This results in full code execution as the user running the iSay process, potentially granting attackers system‑level control over the host. The CVSS score of 9.3 underscores the seriousness of the vulnerability.
Affected Systems
The flaw exists in MOOS‑IvP versions up to 24.8.1, including all builds that incorporate the iSay module. The vendor is moos‑ivp and the product is the MOOS‑IvP software stack commonly used in robotic and unmanned vehicle applications.
Risk and Exploitability
The vulnerability can be triggered remotely by any entity able to send a SAY_MOOS message to the iSay instance. No authentication or additional privileges are required beyond the ability to publish to the SAY_MOOS topic. While EPSS data is not available, the high CVSS score and standard command‑injection exploit path suggest a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its severity and remote nature warrant significant attention.
OpenCVE Enrichment