Impact
The vulnerability arises when the MOOS‑IvP pMarineViewer component accepts NODE_REPORT messages that contain arbitrary, distinct node names without imposing any limit on the number of names it tracks. By sending a large number of unique names, an attacker can force the application to allocate more memory, eventually exhausting available memory and causing the operator display to stall. This lack of input validation leads to an uncontrolled resource consumption scenario.
Affected Systems
The flaw affects MOOS‑IvP pMarineViewer specifically up to and including 24.8.1. Systems running that release are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 classifies the issue as high severity, and the absence of an EPSS score or KEV listing indicates a lack of publicly observed exploitation at the time of assessment. Attackers do not need authentication to submit a crafted NODE_REPORT message, implying that anyone who can reach the MOOS bus or the application’s communication channel can launch the exploit. Given the remote nature of message delivery, a malicious actor with network access to the system can trigger the denial of service by flooding NODE_REPORT messages with distinct node identifiers.
OpenCVE Enrichment