Executive brief
MOOS-IvP uMemWatch is a memory monitoring tool for autonomous marine vehicle software. The vulnerability allows attackers to inject shell commands by providing malicious client names, enabling arbitrary code execution with the privileges of the uMemWatch process. This could compromise robotic systems and the data they collect or control.
Technical details
The vulnerability is a shell command injection flaw in uMemWatch (versions through 24.8.1) where attacker-supplied MOOS client names are used to construct shell commands without proper sanitization. The vulnerable code in MemWatch.cpp passes unquoted client names directly to system calls, allowing injection of shell metacharacters. No authentication is required; an attacker needs only network access to the MOOS middleware to register a malicious client name. Successful exploitation results in arbitrary command execution as the uMemWatch process user. A fix would involve proper quoting or escaping of client names before passing them to shell commands, or preferring direct APIs that do not invoke a shell.
Affected products
- MOOS-IvP uMemWatch through 24.8.1
Timeline
- 2026-09-03: disclosed