PT-2026-85295 · Moos Ivp · Moos-Ivp
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MOOS-IvP versions prior to 24.8.2
Description
A quadratic processing issue exists in
uFldNodeComms where the creation of a new node identity generates a ledger entry and triggers all-pairs distribution work. An attacker can provide an unlimited number of distinct node names within reports to force the shoreside broker into quadratic processing, which results in the delay or prevention of legitimate node report distributions.Recommendations
Update to version 24.8.2 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moos-Ivp