CVE-2026-85449
Received Received - Intake

Memory Exhaustion in MOOS-IvP pMarineViewer

Vulnerability report for CVE-2026-85449, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REPORT data to cause memory exhaustion and stall the operator display without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos-ivp pmarineviewer to 24.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MOOS-IvP pMarineViewer through version 24.8.1 does not restrict the number of unique node identities processed from NODE_REPORT messages. Attackers can send specially crafted data containing an unlimited number of distinct node names, causing the application to consume excessive memory and crash without requiring authentication.

Detection Guidance

Monitor for excessive memory usage in MOOS-IvP pMarineViewer processes. Check for unusually high numbers of distinct node identities in NODE_REPORT messages. Inspect network traffic for crafted NODE_REPORT data from unauthenticated sources.

Impact Analysis

This vulnerability can lead to denial-of-service conditions where the pMarineViewer application becomes unresponsive or crashes due to memory exhaustion. Users may experience system slowdowns, application freezes, or complete shutdowns when processing malicious NODE_REPORT data.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR and HIPAA by enabling denial-of-service attacks that disrupt system availability. Memory exhaustion may cause system crashes, potentially leading to unauthorized data access or loss of critical functionality required for compliance.

Mitigation Strategies

Update MOOS-IvP pMarineViewer to the latest version. Implement input validation for NODE_REPORT messages to limit distinct node identities. Restrict network access to pMarineViewer to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85449. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart