PT-2026-85284 · Moos Ivp · Ufldnodebroker

·

CVE-2026-85435

·

Published

2026-09-03

·

Updated

2026-09-04

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MOOS-IvP uFldNodeBroker versions prior to 24.8.2
Description The uFldNodeBroker fails to validate the source of TRY SHORE HOST messages on the vehicle bus. This allows any publisher to enroll shore routes controlled by an attacker, enabling them to receive bridged vehicle traffic, which may include sensor data and control information.
Recommendations Update MOOS-IvP uFldNodeBroker to a version newer than 24.8.1.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85435

Affected Products

Ufldnodebroker