PT-2024-2606 · Dji · Dji Mavic Mini 3 Pro
Diego Giubertoni
·
Published
2024-03-29
·
Updated
2024-08-26
·
CVE-2023-6949
CVSS v2.0
5.5
Medium
| Vector | AV:A/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DJI Mavic Mini 3 Pro (affected versions not specified)
Description
A Missing Authentication for Critical Function issue affects the HTTP service running on the standard port 80, allowing an attacker to enumerate and download videos and pictures saved on the drone's internal or external memory without requiring authentication. This could enable a remote attacker to gain unauthorized access to protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dji Mavic Mini 3 Pro