CVE-2026-85429
Received Received - Intake

MOOS-IvP uFldNodeComms Node Identity Spoofing Vulnerability

Vulnerability report for CVE-2026-85429, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos-ivp ufldnodecomms to 24.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MOOS-IvP uFldNodeComms through 24.8.1 allows attackers to spoof node identities by crafting NODE_MESSAGE packets with fake source identities. The system trusts the source identity from the message body instead of validating it from the actual connection source.

Detection Guidance

This vulnerability involves spoofed NODE_MESSAGE packets in MOOS-IvP uFldNodeComms. Detection requires monitoring network traffic for packets with inconsistent source identities between the connection source and message body. Inspect logs for unexpected variable notifications from untrusted nodes. No specific commands are provided in the context.

Impact Analysis

An attacker could impersonate legitimate nodes to post arbitrary variable notifications without detection. This could lead to unauthorized control or manipulation of the system, potentially causing incorrect behavior or data corruption.

Compliance Impact

This vulnerability may violate compliance requirements that mandate data integrity and secure communication, such as GDPR's integrity principle or HIPAA's security rule for protecting health information. Unauthorized node impersonation could lead to data breaches or unauthorized access.

Mitigation Strategies

Update MOOS-IvP uFldNodeComms to the latest version (24.8.1 or later). Implement strict validation of node identities by comparing message body sources with connection sources. Restrict network access to trusted nodes only. Monitor for spoofed packets and unauthorized variable notifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85429. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart