Impact
MOOS core-moos through version 10.4.0 contains an authentication bypass flaw in the optional MOOSDB HTTP server. The flaw allows any client that can reach the HTTP port to send requests with variable names and values, resulting in unauthorized modification of MOOS variables, including actuator and override commands. This can compromise the integrity of the system and enable an attacker to influence vehicle behavior or other sensitive control processes.
Affected Systems
The affected product is MOOS core-moos, specifically all releases up to and including version 10.4.0. Users running these versions on any host that exposes the MOOSDB HTTP server are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating a high severity level. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the lack of authentication means any machine that can reach the HTTP service can exploit it. The attack is remote and requires no special credentials, making the risk of exploitation significant for exposed deployments.
OpenCVE Enrichment