CVE-2023-6950
An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself.
An adjacent attacker may perform a denial-of-service attack on the FTP service running on the drone.
March 29, 2024
This issue affects: Mini 3 Pro on all firmwares
CVE-2023-6950
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
3.0
DJI didn't recognize the issue as a vulnerability, for this reason no fix has been delivered. The vulnerability is marked as "disputed".
Diego Giubertoni of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

