PT-2026-85284 · Moos Ivp · Ufldnodebroker
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MOOS-IvP uFldNodeBroker versions prior to 24.8.2
Description
The uFldNodeBroker fails to validate the source of
TRY SHORE HOST messages on the vehicle bus. This allows any publisher to enroll shore routes controlled by an attacker, enabling them to receive bridged vehicle traffic, which may include sensor data and control information.Recommendations
Update MOOS-IvP uFldNodeBroker to a version newer than 24.8.1.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ufldnodebroker