CVE-2026-85449: MOOS-IvP through 24.8.1 pMarineViewer Unbounded Memory Consumption via NODE_REPORT
MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODEREPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODEREPORT data to cause memory exhaustion and stall the operator display without authentication.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments running MOOS-IvP pMarineViewer through version 24.8.1 are affected if an attacker can publish NODE_REPORT messages to the instance. No authentication is required to trigger the condition.
What does an attacker need to do to exploit it?
An attacker must supply crafted NODE_REPORT data containing an unbounded number of distinct node names. pMarineViewer tracks these identities without limiting their number, causing memory consumption to grow until the operator display stalls.
Does this affect confidentiality or data integrity?
The reported impact is availability only. The supplied severity vector indicates no confidentiality or integrity impact, while memory exhaustion can stall the operator display.