CVE-2026-85435

MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 23:17

Updated : 2026-09-08 20:07


NVD link : CVE-2026-85435

Mitre link : CVE-2026-85435

CVE.ORG link : CVE-2026-85435


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity