Impact
This vulnerability allows an unauthenticated attacker to send crafted UDP datagrams to the pShare component of MOOS essential‑moos. The component accepts these packets from any source and republishes them while preserving the attacker‑claimed identity. Consequently, an attacker can inject arbitrary messages into the local MOOS community under a spoofed identity or send malformed packets that cause the pShare process to crash, disrupting mission operations. The primary security impact is integrity compromise through message spoofing and availability degradation via denial of service.
Affected Systems
The issue affects the MOOS essential‑moos package maintained by themoos, specifically versions up to and including 10.0.1. Any deployment of this version that exposes the pShare input routes to external networks is at risk.
Risk and Exploitability
With a CVSS score of 8.8, this weakness is considered high severity. The EPSS score is not available, indicating limited public exploit data, and it is not listed in CISA’s KEV catalog. Nonetheless, the vulnerability can be exploited over the network by sending UDP packets to the pShare input, requiring only network connectivity to the target system. Attackers have no need for privileged access or additional credentials, and the attack can proceed from any remote host that can reach the listening port.
OpenCVE Enrichment