PT-2026-85283 · Moos Ivp · Moos-Ivp

·

CVE-2026-85434

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE BROKER PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85434

Affected Products

Moos-Ivp