Impact
MOOS core‑moos versions up to 10.4.0 allow an attacker who can authenticate to the MOOSDB to send messages that carry an arbitrary source identifier. The database does not verify that the source supplied on the wire matches the authenticated connection, enabling the attacker to re‑attribute writes to other clients and cancel their subscriptions. This flaw can be used to disrupt service and confuse client identity recognition.
Affected Systems
The affected product is MOOS core‑moos from themoos, with any release through version 10.4.0. Versions prior to 10.4.0 are also vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity vulnerability. No EPSS data is available, but the flaw is not listed in the CISA KEV catalog. An attacker requires valid network access and the ability to authenticate to MOOSDB; once authenticated, the attacker can exploit the missing identity validation to forge message origins and cause denial of service by canceling third‑party subscriptions. The risk is significant for deployments that rely on strict client attribution for data integrity.
OpenCVE Enrichment