Impact
The vulnerability in MOOS essential-moos pShare allows any publisher to send PSHARE_CMD messages that are not properly authorized. These messages can instruct the system to create new listeners on arbitrary addresses and redirect or duplicate bus traffic. If an attacker controls the input, they can open open ports or bind to addresses they otherwise cannot access, effectively hijacking the message bus traffic for exfiltration or traffic manipulation. The flaw is categorized as CWE-862, an insecure direct object reference, and carries a CVSS score of 9.3, indicating a high severity outcome.
Affected Systems
The issue affects the themoos:essential-moos product up through version 10.0.1. All installations relying on pShare in this series are vulnerable unless they have been patched to a revision that includes the fix. The vulnerability originates from the Share.cpp component of the essentials/pShare module.
Risk and Exploitability
With a CVSS of 9.3 and no viable EPSS data, the risk is considered high. Attackers can exploit the flaw by sending crafted PSHARE_CMD messages via any standard publisher channel, requiring no special privileges or credentials. Because the system fails to enforce authorization checks, an attacker can redirect traffic to attacker-controlled destinations, causing confidentiality loss, data tampering, or service disruption. The vulnerability is not listed in the CISA KEV catalog, but its severity suggests that it is likely to be targeted by threat actors once disclosed publicly.
OpenCVE Enrichment