A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a crafted payload due to a missing input sanity check in the v2_pack_array_to_msg function implemented in the libv2_sdk.so library imported by the v2_sdk_service binary implementing the service, potentially leading to a memory information leak or an arbitrary code execution. Affected models are Mavic 3 Pro until v01.01.0300, Mavic 3 until v01.00.1200, Mavic 3 Classic until v01.00.0500, Mavic 3 Enterprise until v07.01.10.03, Matrice 300 until v57.00.01.00, Matrice M30 until v07.01.0022 and Mini 3 Pro until v01.00.0620.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Sep 2024 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dji
Dji matrice 300 Firmware Dji matrice M30 Firmware Dji mavic 3 Firmware Dji mavic 3 Pro Firmware Dji mini 3 Pro Firmware |
|
Weaknesses | CWE-20 | |
CPEs | cpe:2.3:o:dji:matrice_300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dji:matrice_m30_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dji:mavic_3_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dji:mavic_3_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dji:mini_3_pro_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Dji
Dji matrice 300 Firmware Dji matrice M30 Firmware Dji mavic 3 Firmware Dji mavic 3 Pro Firmware Dji mini 3 Pro Firmware |
|
Metrics |
ssvc
|
Mon, 30 Sep 2024 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 CWE-787 |
MITRE
Status: PUBLISHED
Assigner: Nozomi
Published: 2024-04-02T10:31:30.487Z
Updated: 2024-09-30T10:03:29.786Z
Reserved: 2023-12-19T15:38:30.829Z
Link: CVE-2023-51456
Vulnrichment
Updated: 2024-08-02T22:32:10.053Z
NVD
Status : Awaiting Analysis
Published: 2024-04-02T11:15:50.717
Modified: 2024-09-30T10:15:04.343
Link: CVE-2023-51456
Redhat
No data.