MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
Metrics
Affected Vendors & Products
References
History
Sat, 05 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themoos
Themoos core-moos |
|
| Vendors & Products |
Themoos
Themoos core-moos |
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues. | |
| Title | MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T22:38:20.333Z
Updated: 2026-09-05T02:21:59.167Z
Reserved: 2026-09-03T19:50:44.220Z
Link: CVE-2026-85424
Updated: 2026-09-05T02:21:55.553Z
Status : Awaiting Analysis
Published: 2026-09-03T23:17:21.170
Modified: 2026-09-08T20:07:17.943
Link: CVE-2026-85424
No data.