Remote Code Execution Vulnerability in Parrot ANAFI Web Server
CVE-2019-3945

7.5HIGH

Key Information:

Vendor

Parrot

Vendor
CVE Published:
1 April 2020

What is CVE-2019-3945?

A vulnerability exists in the web server of the Parrot ANAFI drone. This issue arises when the SDK command 'Common_CurrentDateTime' is sent to the control service, with a date length that exceeds expected parameters. Such a scenario can cause the web server to crash, affecting the drone's operations and potentially leading to unauthorized access or control issues.

Affected Version(s)

Parrot ANAFI Parrot ANAFI Firmware versions prior to 1.5.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.