Security · MOOS-IvP MOOS-IvP uFldNodeComms

MOOS-IvP uFldNodeComms Allows Node Message Source Spoofing Through 24.8.1

MOOS-IvP's uFldNodeComms module through version 24.8.1 trusts the source node identity supplied in the message body instead of validating it against the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.