Impact
The vulnerability resides in the uFldNodeComms module of MOOS‑IvP versions up to 24.8.1. Each time a new node identity is received, the module creates a ledger entry and triggers all‑pairs distribution work. An attacker can inject an arbitrary number of distinct node names in reports, causing the broker to perform quadratic processing. This can delay or block the delivery of legitimate node reports, effectively denying service to the system. The weakness corresponds to CWE‑407, Excessive Computation.
Affected Systems
Systems running MOOS‑IvP version 24.8.1 or earlier are affected. The vendor identified is moos‑ivp, and the product is MOOS‑IvP. No specific sub‑versions within the range are listed, so any build prior to a fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score is not available, so the current public likelihood of exploitation is unknown. The vulnerability is not listed in CISA KEV. Attackers can most likely exploit it by sending crafted messages containing many unique node names to the broker over the network, inferred from the description that an attacker supplies distinct node names in reports. If the broker processes these messages, it will consume significant CPU time and may become unresponsive, leading to a denial of service.
OpenCVE Enrichment