Impact
MOOS core‑moos versions up to 10.4.0 contain a buffer over‑read in the CMOOSCommPkt module that allows an unauthenticated attacker to trigger out‑of‑bounds memory reads by sending a short four‑byte packet to the MOOSDB port during deserialization. This flaw can expose arbitrary memory contents before the connection is authenticated, potentially leaking sensitive data. The weakness is a classic CWE‑125 read outside bounds.
Affected Systems
The affected product is themoos core‑moos, versions ranging from the initial release through 10.4.0. Any installation using these releases without an upgrade is susceptible.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. Although no EPSS value is available, the lack of a KEV listing does not diminish the risk of remote exploitation via an open TCP port. External attackers can initiate a connection, send the crafted packet, and read memory without authentication, indicating a simple remote attack path that requires no privileged credentials.
OpenCVE Enrichment