Impact
The uFldNodeComms module in MOOS‑IvP accepts NODE_MESSAGE packets and relies solely on the source node identity provided in the packet body without verifying it against the actual network connection. An attacker that can send packets to the MOOS infrastructure can therefore forge the identity of any trusted node. By transmitting a crafted packet containing a spoofed source identifier, the attacker can have the system publish arbitrary variable notifications as if they originated from that node. This allows an attacker to inject data and impersonate other nodes without any credentials.
Affected Systems
The vulnerability impacts the MOOS‑IvP middleware (moos‑ivp:moos‑ivp) in all releases up to and including version 24.8.1. The affected component is the uFldNodeComms node responsible for processing incoming node messages. Administrators should verify whether newer releases contain the source‑validation fix.
Risk and Exploitability
With a CVSS score of 8.7 the flaw is categorized as high severity. The attack simply requires the attacker to send forged NODE_MESSAGE packets to the uFldNodeComms endpoint, so any host that can reach the MOOS network can exploit it. Because the spoofed data is trusted by downstream consumers, the integrity—and potentially the availability—of the MOOS system is at risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the absence of credential or device restrictions makes the risk still significant for organizations exposing MOOS nodes to external networks.
OpenCVE Enrichment