CVE-2026-85429: MOOS-IvP through 24.8.1 uFldNodeComms Node Message Source Spoofing
MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODEMESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication, privileges, or user interaction?
No. The supplied CVSS vector indicates network-reachable exploitation with low attack complexity, no required privileges, and no user interaction.
Which versions are known to be affected?
uFldNodeComms in MOOS-IvP through version 24.8.1 is identified as affected. The provided data does not specify the first fixed release.
What is the expected security impact?
The reported impact is high integrity impact: an attacker can impersonate a node and cause arbitrary variable notifications to be posted. The supplied CVSS vector indicates no direct confidentiality or availability impact.