Missing Authentication for Critical Function

CVE-2023-6949

Summary

A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.

Impact

An adjacent attacker may exfiltrate pictures and recorder videos from the drone memory.

Issue Date

March 29, 2024

Affects

This issue affects: Mini 3 Pro on all firmwares.

CVE Name

CVE-2023-6949

CVSS Details

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CVSS Score

5.2

Solution

DJI didn't recognize the issue as a vulnerability, for this reason no fix has been delivered. The vulnerability is marked as "disputed".

Mitigations

Acknowledgements

Diego Giubertoni of Nozomi Networks

Nozomi Threat Intelligence

Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.

Learn more

Latest Labs Blogs

Threat Actor Activity Related to the Iran Conflict

Read

Fuzzing Protocol Implementations: 10 Vulnerabilities in the P-Net PROFINET Library

Read

Major Power Outage Hits Spain and Portugal: Spotlight on Critical Energy Infrastructure Vulnerabilities 

Read
View All

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.