MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 23:17
Updated : 2026-09-08 20:07
NVD link : CVE-2026-85451
Mitre link : CVE-2026-85451
CVE.ORG link : CVE-2026-85451
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
