CyberRota Analysis
AI-GeneratedThe vulnerability affects MOOS core-moos versions up to 10.4.0, where inadequate validation of client identity in MOOSDB message processing allows authenticated attackers to impersonate other clients by manipulating source identifiers in serialized messages. This exploitation can lead to unauthorized message attribution and the cancellation of third-party subscriptions, posing significant risks to data integrity and service availability. Organizations using this software, particularly those relying on secure client communications, should prioritize immediate remediation efforts.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source attribution.