Impact
MOOS-IvP up to version 24.8.1 contains a flaw where the uMemWatch component constructs shell commands by concatenating attacker‑controlled MOOS client names without any sanitization. This omission permits an attacker to embed shell metacharacters such as redirection symbols or pipes, enabling execution of arbitrary commands with the privileges of the uMemWatch process. The weakness is a classic command injection problem identified as CWE‑78, and it can result in full compromise of the host running the affected process.
Affected Systems
All installations of MOOS‑IvP that include the uMemWatch feature are vulnerable, specifically those with versions from the earliest release through 24.8.1. The vendor is moos‑ivp and the product is MOOS‑IvP. No specific version beyond 24.8.1 has been listed as affected, suggesting newer releases may have addressed the issue.
Risk and Exploitability
The CVSS score of 9.3 reflects a critical level of severity, indicating that a successful exploitation results in complete loss of confidentiality, integrity, and availability. No EPSS score is available, so the exact likelihood of exploitation in the wild is unknown, but the absence of a KEV listing does not mitigate the high impact. Based on the description it is inferred that the attack vector requires the ability to register or manipulate MOOS client names, likely through the MOOS client interface, and the attacker may execute commands as the uMemWatch process user once the injection succeeds.
OpenCVE Enrichment