CVE-2023-31191
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2023-31191 is a vulnerability affecting the DroneScout ds230 Remote ID receiver from BlueMark Innovations. This issue involves an information loss vulnerability that can be exploited through traffic injection, allowing an attacker to force the receiver to drop real Remote ID (RID) information and transmit fake JSON encoded MQTT messages instead. The adjacent channel suppression algorithm present in DroneScout ds230 firmware versions 20211210-1627 through 20230329-1042 is the culprit. An attacker can inject high power spoofed Open Drone ID (ODID) messages, which results in the system integrator's MQTT broker having no access to the drones' real RID information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions