Impact
The vulnerability allows an attacker to degrade the availability of the Parrot AR.Drone by initiating IPv4 flood attacks. By sending large volumes of SYN or UDP packets, the device can be overwhelmed, causing loss of video streaming and control capabilities. This vulnerability is a classic denial‑of‑service flaw based on unprotected network interfaces.
Affected Systems
Parrot AR.Drone version 1 and version 2 are affected. No other product or firmware versions are listed as impacted.
Risk and Exploitability
The attack vector is network‑based and requires only the capability to send packets to the drone’s IP address; no authentication is needed. With no documented mitigation or patch at the time of this analysis, readily available tools could exploit the flaw. The CVSS score of 7.5 indicates a high‑severity denial‑of‑service vulnerability, and the EPSS score is not available, so the likelihood of exploitation cannot be precisely quantified. The vulnerability is not listed in the CISA KEV catalog. Overall, the risk remains high due to the ease of mounting a flood attack and the critical impact on drone availability.
OpenCVE Enrichment