Impact
A flaw in MOOS‑IvP 24.8.1 permits insufficient validation of variable names extracted from alog files. When a crafted alog file contains backslash sequences, the SplitHandler will create or overwrite files beyond its configured split directory. The vulnerability therefore allows modification or creation of arbitrary files, potentially compromising system integrity.
Affected Systems
The affected product is MOOS‑IvP version 24.8.1. All installations of this version on Windows platforms that use the SplitHandler to parse alog files are vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The EPSS score is not available, indicating insufficient data on exploitation probability, and the vulnerability is not listed in KEV. The likely attack vector is an attacker supplying crafted alog files—either locally or via an upload mechanism that the application accepts—so that the SplitHandler will process them. Successful exploitation would enable an attacker to write or modify arbitrary files on the affected host, threatening the integrity of the system.
OpenCVE Enrichment