CVE-2026-85435: MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRYSHOREHOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
MOOS-IvP uFldNodeBroker versions through 24.8.1 are affected. The provided information does not identify a fixed release version.
What access does an attacker need?
An attacker needs the ability to publish TRY_SHORE_HOST messages on the vehicle bus. No authentication, privileges, or user interaction are required according to the supplied vector.
What could an attacker obtain after exploitation?
An attacker can enroll attacker-controlled shore routes and receive bridged vehicle traffic. This traffic can include sensor data and control information.