Security
Security · MOOS-IvP MOOS-IvP uFldShoreBroker
MOOS-IvP uFldShoreBroker Flaw Allows Bridge Route Injection via Unverified Node Pings
MOOS-IvP through version 24.8.1 does not verify the authenticity of node ping messages in its uFldShoreBroker module before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages containing crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
Read the original coverage at CVE.org
Captured 24 minutes ago