CyberRota Analysis
AI-GeneratedThe MOOS core-moos versions up to 10.4.0 are critically vulnerable due to a lack of authentication in their wire protocol, enabling unauthenticated clients to connect and perform privileged operations such as clearing databases. This vulnerability allows attackers to bypass security checks and execute commands that can disrupt operations and compromise data integrity. Organizations using this software should prioritize immediate remediation to prevent potential exploitation and data loss.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.