CVE-2023-51452
CVSS 3.1 Score 3.0 of 10 (low)
Details
Summary
CVE-2023-51452 is a vulnerability affecting DJI drone devices running the v2_sdk_service on port 10000. This issue involves improper input validation in the pull_file_v2_proc function of the libv2_sdk.so library, which is used by the dji_vtwo_sdk binary implementing the service. An attacker can exploit this vulnerability by sending a crafted payload to trigger a missing input size check, resulting in a crash of the service. This denial-of-service attack impacts several DJI drone models, including the Mavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30, and Mini 3 Pro, with various affected firmware versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.