Impact
The vulnerability resides in the pAntler component of MOOS essential‑moos through 10.0.1, where malicious Run entries in a MISSION_FILE are parsed and executed via execvp() without any authentication checks. This flaw enables an attacker to run arbitrary code on the host running the pAntler service, compromising confidentiality, integrity, and availability of the affected system. The weakness corresponds to CWE‑494, which describes the failure to properly validate or sanitize data before passing it to a system‑level interpreter.
Affected Systems
The issue affects the MOOS essential‑moos distribution, specifically versions through 10.0.1. The software is maintained by themoos and is used in marine navigation and robotic applications that rely on MOOSDB for inter-process communication. No other products or vendors are listed as affected.
Risk and Exploitability
Given the CVSS score of 9.2, the vulnerability is considered high severity. No EPSS score is available, but the lack of authentication requirements suggests that exploitation would be straightforward on a system exposing the MOOSDB to potential attackers. The vulnerability is not currently listed in the CISA KEV catalog, indicating no widespread exploitation has yet been reported; however, the attack surface and the ability to execute code remotely make it a critical threat for environments where unauthenticated MISSION_FILE messages could be sent.
OpenCVE Enrichment