CyberRota Analysis
AI-GeneratedMOOS-IvP uFldNodeComms versions up to 24.8.1 are vulnerable due to improper validation of source node identities, allowing attackers to craft NODE_MESSAGE packets with spoofed identities. This flaw enables unauthorized impersonation of nodes, leading to the potential posting of arbitrary variable notifications and disruption of communication integrity. Organizations utilizing affected versions should prioritize remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.