CyberRota Analysis
AI-GeneratedThe vulnerability allows attackers to exploit the uMemWatch component of MOOS-IvP by injecting shell metacharacters into client names, leading to the execution of arbitrary commands with the privileges of the uMemWatch process. This critical flaw poses a significant risk to systems using affected versions, particularly those that rely on MOOS-IvP for mission-critical operations. Organizations utilizing this software should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.