CVE-2026-85449 HIGH

CVE-2026-85449: MOOS-IvP through 24.8.1 pMarineViewer Unbounded Memory Consumption via NODE_REPORT

Vendor Moos-Ivp
Product moos-ivp
Weakness CWE-770 · Uncontrolled resource consumption
Published September 3, 2026
Last update September 8, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REPORT data to cause memory exhaustion and stall the operator display without authentication.

Key dates

02Disclosure timeline

September 3, 2026 CVE published
September 8, 2026 Record updated

Related vulnerabilities

04Related CVE