PT-2024-2603 · Dji · Dji Mavic Mini 3 Pro

Diego Giubertoni

·

Published

2024-03-29

·

Updated

2024-09-30

·

CVE-2023-6950

CVSS v3.1

3.0

Low

VectorAV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions DJI Mavic Mini 3 Pro (affected versions not specified)
Description The issue is related to an Improper Input Validation vulnerability in the FTP service. It could allow an attacker to craft a malicious packet with a malformed path provided to the FTP SIZE command, leading to a denial-of-service attack of the FTP service itself. This vulnerability may be exploited by a remote attacker, resulting in a service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02670
CVE-2023-6950

Affected Products

Dji Mavic Mini 3 Pro