Description
MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
Published: 2026-09-03
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MOOS‑IvP versions up to 24.8.1 contain buffer overflow flaws in the IvP function string decoders. The decoder trusts attacker‑controlled length fields and does not validate that the actual payload matches the declared size. An attacker can craft a malicious encoded string with a mismatched length, causing a heap or stack overflow. If successfully exploited, the attacker may gain remote code execution through MOOS variables or alog files.

Affected Systems

The affected product is MOOS‑IvP from the moos‑ivp project. All releases through version 24.8.1 are vulnerable. Earlier releases prior to the acknowledgement of this issue are also impacted until the patch is applied.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity level. Although an EPSS score is not available, the vulnerability is not yet listed in the CISA KEV catalog, which means no publicly confirmed exploitation at this time. The attack path requires the ability to send malicious encoded strings to a running MOOS‑IvP instance, either by injecting data into MOOS variables or by placing a crafted alog file. Because the vulnerability touches heap and stack memory, a successful overflow can lead to arbitrary code execution, exposing the system to full compromise.

Generated by OpenCVE AI on September 3, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MOOS‑IvP to the latest released version that incorporates the fix for the function string decoder buffer overflow.
  • Restrict the MOOS network so that only trusted hosts can publish variables or alog files to the vulnerable component, thereby limiting the attack surface.
  • Remove or quarantine any untrusted variable entries and alog files that may contain maliciously crafted encoded strings as a temporary mitigation.

Generated by OpenCVE AI on September 3, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
Title MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T22:38:29.210Z

Reserved: 2026-09-03T19:50:56.573Z

Link: CVE-2026-85437

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T23:17:23.103

Modified: 2026-09-03T23:17:23.103

Link: CVE-2026-85437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T23:30:11Z

Weaknesses