PT-2026-85286 · Moos Ivp · Moos-Ivp
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MOOS-IvP versions prior to 24.8.2
Description
Multiple buffer overflow issues exist in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially leading to remote code execution through MOOS variables or alog files.
Recommendations
Update MOOS-IvP to version 24.8.2 or later.
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moos-Ivp