Impact
The vulnerability arises when the uFldNodeBroker component of MOOS‑IvP fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus. This flaw represents an instance of improper input validation (CWE‑345), allowing any publisher on the bus to enroll attacker‑controlled shore routes. By sending forged shore route messages, an adversary can receive bridged vehicle traffic that includes sensitive sensor data and control information, effectively exfiltrating data and potentially impacting vehicle operation.
Affected Systems
This flaw affects installations of MOOS‑IvP through version 24.8.1, specifically the uFldNodeBroker component responsible for shore route enrollment. All older or identical releases without the official fix remain vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical vulnerability. The lack of authentication or source verification makes it exploitable by any entity with access to the vehicle bus, typically an internal or compromised node. No EPSS score is available and the issue is not yet listed in the CISA KEV catalog, but the ability to intercept and redirect vehicle traffic imposes a high confidentiality and integrity risk.
OpenCVE Enrichment