CVE-2023-6949

CVSS 3.1 Score 5.2 of 10 (medium)

Details

Published Apr 2, 2024
Updated: Aug 2, 2024
CWE ID 306

Summary

CVE-2023-6949 is a vulnerability affecting the HTTP service on the DJI Mavic Mini 3 Pro drone, running on the standard port 80. This issue is classified as a Missing Authentication for Critical Function (MACF) vulnerability. An attacker can exploit this flaw to enumerate and download videos and pictures saved on the drone's internal or external memory without the need for authentication. This lack of security could potentially result in sensitive data being accessed and stolen. Users are advised to apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share