Impact
MOOS‑IvP versions up to 24.8.1 contain buffer overflow flaws in the IvP function string decoders. The decoder trusts attacker‑controlled length fields and does not validate that the actual payload matches the declared size. An attacker can craft a malicious encoded string with a mismatched length, causing a heap or stack overflow. If successfully exploited, the attacker may gain remote code execution through MOOS variables or alog files.
Affected Systems
The affected product is MOOS‑IvP from the moos‑ivp project. All releases through version 24.8.1 are vulnerable. Earlier releases prior to the acknowledgement of this issue are also impacted until the patch is applied.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity level. Although an EPSS score is not available, the vulnerability is not yet listed in the CISA KEV catalog, which means no publicly confirmed exploitation at this time. The attack path requires the ability to send malicious encoded strings to a running MOOS‑IvP instance, either by injecting data into MOOS variables or by placing a crafted alog file. Because the vulnerability touches heap and stack memory, a successful overflow can lead to arbitrary code execution, exposing the system to full compromise.
OpenCVE Enrichment