CVE-2023-6949

A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.
Configurations

No configuration.

History

02 Apr 2024, 14:15

Type Values Removed Values Added
Summary
  • (es) ** EN DISPUTA ** Un problema de falta de autenticación para funciones críticas que afecta el servicio HTTP que se ejecuta en el DJI Mavic Mini 3 Pro en el puerto estándar 80 podría permitir a un atacante enumerar y descargar videos e imágenes guardados en la memoria interna o externa del dron sin necesidad cualquier tipo de autenticación.
Summary (en) ** DISPUTED ** A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication. (en) A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.

02 Apr 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-02 11:15

Updated : 2024-04-11 01:23


NVD link : CVE-2023-6949

Mitre link : CVE-2023-6949

CVE.ORG link : CVE-2023-6949


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function