Executive brief
MOOS-IvP is a set of middleware modules that provide autonomy control and inter-node communication for robotic platforms, including autonomous marine vehicles. A vulnerability in uFldNodeComms allows attackers to spoof the source identity of network messages, enabling an attacker to impersonate authorized nodes and inject arbitrary commands or data into the system, potentially compromising vehicle behavior or mission data integrity.
Technical details
The vulnerability is a lack of source identity validation in uFldNodeComms. The component trusts the source node identity contained within the message body of NODE_MESSAGE packets rather than validating it against the actual network connection source. An attacker with network access can craft malicious NODE_MESSAGE packets with forged source identities and post arbitrary variable notifications without proper authentication, allowing impersonation of legitimate nodes and unauthorized command injection.
Affected products
- MOOS-IvP uFldNodeComms through 24.8.1
Timeline
- 2026-09-03: disclosed