CVE-2026-85431
MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.90% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345
- Source
- disclosure@vulncheck.com
References
- https://github.com/themoos/essential-moos
- https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34cdaf5f6/Essentials/pMOOSBridge/MOOSUDPLink.cpp#L21
- https://github.com/themoos/essential-moos/commit/d8441eac57d04ee89e7b82723480d10a558b45d6
- https://github.com/themoos/essential-moos/pull/19
- https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pmoosbridge-unauthenticated-udp-packet-injection
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.