Description
MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
Published: 2026-09-03
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when the uFldNodeBroker component of MOOS‑IvP fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus. This flaw represents an instance of improper input validation (CWE‑345), allowing any publisher on the bus to enroll attacker‑controlled shore routes. By sending forged shore route messages, an adversary can receive bridged vehicle traffic that includes sensitive sensor data and control information, effectively exfiltrating data and potentially impacting vehicle operation.

Affected Systems

This flaw affects installations of MOOS‑IvP through version 24.8.1, specifically the uFldNodeBroker component responsible for shore route enrollment. All older or identical releases without the official fix remain vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical vulnerability. The lack of authentication or source verification makes it exploitable by any entity with access to the vehicle bus, typically an internal or compromised node. No EPSS score is available and the issue is not yet listed in the CISA KEV catalog, but the ability to intercept and redirect vehicle traffic imposes a high confidentiality and integrity risk.

Generated by OpenCVE AI on September 4, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a version later than 24.8.1 that enforces source validation for TRY_SHORE_HOST messages.
  • If immediate upgrade is not possible, configure the vehicle bus or application firewall to reject TRY_SHORE_HOST messages from unknown or unauthenticated publishers, ensuring only trusted nodes can request shore route enrollment.
  • As a last resort, disable shore route enrollment entirely to prevent unauthenticated route registration until a patch or proper authentication mechanism is in place.

Generated by OpenCVE AI on September 4, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
Title MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T22:38:27.809Z

Reserved: 2026-09-03T19:50:55.884Z

Link: CVE-2026-85435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T23:17:22.787

Modified: 2026-09-03T23:17:22.787

Link: CVE-2026-85435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T00:30:12Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity