Impact
The vulnerability is a remote process termination flaw in the SuicidalSleeper component of MOOS core‑moos. It arises from a hard‑coded passphrase that authorizes multicast commands. Any peer that can reach the default multicast group and port can enumerate MOOS processes and issue a termination command, causing the targeted process to shut down. This results in loss of availability and potential disruption of a mission‑critical application.
Affected Systems
The flaw affects the themoos core‑moos software, specifically versions 10.4.0 and earlier. The vulnerability is present in all builds that ship with the hard‑coded multicast passphrase in the SuicidalSleeper module. The product is open source, so any deployment of core‑moos in a robotic or maritime environment may be impacted unless a patched version is used.
Risk and Exploitability
Assessments show a CVSS score of 7.1, indicating moderate to high severity, but the EPSS score is not available, so the exact exploitation probability cannot be determined. No listing in the CISA KEV catalog is reported. The attack requires network proximity to the multicast group and no authentication beyond the default passphrase, making exploitation straightforward for adversaries who can establish network visibility within the same subnet or multicast domain.
OpenCVE Enrichment