CVE-2026-85435
Received Received - Intake

MOOS-IvP uFldNodeBroker Shore Route Injection Vulnerability

Vulnerability report for CVE-2026-85435, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos-ivp ufldnodebroker to 24.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MOOS-IvP uFldNodeBroker through version 24.8.1 does not verify the origin of TRY_SHORE_HOST messages on the vehicle bus. This allows any message publisher to add attacker-controlled shore routes. Attackers can send fake shore route messages to intercept vehicle traffic including sensor data and control information.

Detection Guidance

Detecting this vulnerability requires monitoring for unauthorized TRY_SHORE_HOST messages on the vehicle bus. Check MOOS-IvP logs for unexpected shore route enrollments or traffic bridging. Inspect network traffic for suspicious shore route advertisements using tools like tcpdump or Wireshark to capture and analyze vehicle bus communications.

Impact Analysis

An attacker could gain access to sensitive vehicle data such as sensor readings and control commands. They might manipulate or eavesdrop on communications between vehicles and shore systems, potentially leading to unauthorized control or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using affected systems may face compliance violations and legal consequences.

Mitigation Strategies

Immediately update MOOS-IvP uFldNodeBroker to version 24.8.1 or later. Restrict message publishing permissions on the vehicle bus to trusted entities only. Implement input validation for TRY_SHORE_HOST messages to ensure only authorized sources can enroll shore routes. Monitor network traffic for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85435. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart