CVE-2023-6950

CVSS 3.1 Score 3.0 of 10 (low)

Details

Published Apr 2, 2024
Updated: Aug 2, 2024
CWE ID 20

Summary

CVE-2023-6950 is a newly identified vulnerability impacting the FTP service on the DJI Mavic Mini 3 Pro. Maliciously crafted packets containing malformed paths, provided to the FTP SIZE command, can trigger an improper input validation issue. This vulnerability could lead to a denial-of-service (DoS) attack against the FTP service itself. An attacker can exploit this flaw to disrupt the normal functioning of the FTP server, potentially affecting data transmission and management processes. Users are advised to update their DJI Mavic Mini 3 Pro firmware to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share