Impact
The vulnerability allows an attacker to send an unbounded REALMCAST_REQ subscription to the pRealm component of MOOS‑IvP without the service validating the requested duration or the number of variables. The effect is that the service generates excessive output for an unlimited period, exhausting CPU, memory, or I/O resources, and thereby causing a denial of service. This weakness is a classic case of resource exhaustion, reflected in CWE‑770.
Affected Systems
The flaw exists in MOOS‑IvP up through version 24.8.1, specifically in the pRealm module that handles pipeway subscriptions. Users running any affected release should consider these components as vulnerable, especially if pRealm is exposed to untrusted networks.
Risk and Exploitability
With a CVSS score of 8.7 the issue is categorized as high severity. No EPSS score is published, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via the network interface on which pRealm listens; any host with network reach to that interface can craft a REALMCAST_REQ that requests a very long duration and a large variable set to trigger resource exhaustion. No special privileges are required beyond connectivity to the service.
OpenCVE Enrichment