PT-2026-85294 · Moos Ivp · Moos-Ivp
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MOOS-IvP versions prior to 24.8.2
Description
A denial of service issue exists in the
Demuxer::addMuxPacket() function. The system trusts the packet count declared in mux headers without proper validation, allowing attackers to specify arbitrarily large packet counts. This leads to unbounded memory allocation, which exhausts system resources and results in service unavailability.Recommendations
Update MOOS-IvP to version 24.8.2 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moos-Ivp