CVE-2023-31191

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jul 11, 2023
Updated: Jul 20, 2023
CWE ID 221

Summary

CVE-2023-31191 is a vulnerability affecting the DroneScout ds230 Remote ID receiver from BlueMark Innovations. This issue involves an information loss vulnerability that can be exploited through traffic injection, allowing an attacker to force the receiver to drop real Remote ID (RID) information and transmit fake JSON encoded MQTT messages instead. The adjacent channel suppression algorithm present in DroneScout ds230 firmware versions 20211210-1627 through 20230329-1042 is the culprit. An attacker can inject high power spoofed Open Drone ID (ODID) messages, which results in the system integrator's MQTT broker having no access to the drones' real RID information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share