Security · MOOS-IvP MOOS-IvP uFldShoreBroker

MOOS-IvP uFldShoreBroker Flaw Allows Bridge Route Injection via Unverified Node Pings

MOOS-IvP through version 24.8.1 does not verify the authenticity of node ping messages in its uFldShoreBroker module before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages containing crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.