Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moos-ivp
Moos-ivp moos-ivp |
|
| Vendors & Products |
Moos-ivp
Moos-ivp moos-ivp |
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses. | |
| Title | MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping | |
| Weaknesses | CWE-345 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T02:25:21.488Z
Reserved: 2026-09-03T19:50:55.525Z
Link: CVE-2026-85434
Updated: 2026-09-05T02:25:17.938Z
Status : Received
Published: 2026-09-03T23:17:22.643
Modified: 2026-09-05T03:17:24.303
Link: CVE-2026-85434
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:21:30Z