Impact
MOOS‑IvP through version 24.8.1 has a remote code execution vulnerability in the alogsplit utility. The SplitHandler::handlePreCheckSplitDir() function does not sanitize shell metacharacters embedded in log file names or in the --dir parameter, allowing an attacker to inject arbitrary shell commands that will execute with the privileges of the user running alogsplit.
Affected Systems
All installations of MOOS‑IvP version 24.8.1 and earlier are vulnerable. The flaw resides in the alogsplit LogHandler component of the MOOS‑IvP package.
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑severity risk. EPSS data is unavailable, so the exact likelihood of exploitation cannot be quantified. Attacks require the attacker to provide a malicious log filename or --dir argument when alogsplit is run, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. Nonetheless, the potential for an attacker to execute arbitrary commands remains significant.
OpenCVE Enrichment