Vulnerability Description
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/themoos/core-moos
- https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f
- https://github.com/themoos/core-moos/commit/488806a07db9f21eea124f48a9c0392f058f
- https://github.com/themoos/core-moos/pull/85
- https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-remote-proces
FAQ
What is CVE-2026-85451?
CVE-2026-85451 is a vulnerability with a CVSS score of 7.1 (HIGH). MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-...
How severe is CVE-2026-85451?
CVE-2026-85451 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-85451?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.