Remote Denial of Service in Parrot Bebop Wi-Fi Device
CVE-2022-46416

9.1CRITICAL

Key Information:

Vendor

Parrot

Vendor
CVE Published:
27 March 2023

What is CVE-2022-46416?

The Parrot Bebop 4.7.1 is vulnerable to a Remote Denial of Service, which allows attackers to disrupt legitimate terminal connections. This is achieved by exploiting the DHCP IP address pool, where an attacker first connects to the device's internal Wi-Fi network and then floods it with DHCP request packets. This action can lead to exhaustion of available IP addresses, effectively preventing authorized users from connecting to the network.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.