CVE-2023-6951
CVSS 3.1 Score 6.6 of 10 (medium)
Details
Summary
CVE-2023-6951 is a Use of Weak Credentials vulnerability that affects the Wi-Fi networks generated by certain DJI drone models. An attacker can exploit this weakness to derive the WPA2 PSK key and gain unauthorized access to the drone's Wi-Fi network. This breach enables the attacker to decrypt traffic between the drone and its connected Android/IOS device during QuickTransfer mode, potentially leading to unauthorized interaction with network services and data theft. Affected DJI drone models include Mavic 3 Pro up to v01.01.0300, Mavic 3 up to v01.00.1200, Mavic 3 Classic up to v01.00.0500, Mavic 3 Enterprise up to v07.01.10.03, Matrice 300 up to v57.00.01.00, Matrice M30 up to v07.01.0022, and Mini 3 Pro up to v01.00.0620.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.