PT-2026-85293 · Moos Ivp · Moos-Ivp
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MOOS-IvP versions prior to 24.8.2
Description
A buffer over-read occurs in the
isQuoted(), isBraced(), and isChevroned() functions. These functions strip whitespace from input but continue to index using the original string length, allowing an attacker to read past buffer bounds and access adjacent memory by sending NODE REPORT messages containing leading or trailing whitespace.Recommendations
Update MOOS-IvP to version 24.8.2 or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moos-Ivp