ZeroHour

CVE-2021-44319

large

Unauthenticated Wi-Fi Deauthentication DoS in Parrot AR.Drone 1 and AR.Drone 2

CVSS 3.1
7.5 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2021-44319 is a denial-of-service weakness in the Parrot AR.Drone 1 and AR.Drone 2, whose Wi-Fi control link can be knocked offline by a Wi-Fi deauthentication attack. A remote, unauthenticated attacker within wireless range of the drone's Wi-Fi network can trigger the flaw by sending deauthentication frames that force the drone to drop its connection to the controller. The attacker gains an availability-only impact (CVSS 3.1 7.5, A:H): the operator loses control of the drone mid-flight, which can lead to an uncontrolled descent or crash, with no confidentiality or integrity impact. Owners and operators of these discontinued consumer drones are the affected population. Exploitation status is quiet: no public proof-of-concept is known, it is not in CISA KEV, and EPSS assigns a 0.5% probability of exploitation in the next 30 days, although deauthentication tooling is trivially available to any attacker with basic wireless equipment.

What to do: No patched firmware is documented in the available data; check Parrot's support channels for the latest AR.Drone 1/2 firmware before flying. Because deauthentication frames are unauthenticated 802.11 management frames that encryption settings alone cannot block, mitigate operationally by flying away from dense or congested 2.4 GHz Wi-Fi environments and treating mid-flight disconnects as the primary risk. If a controller link drops unexpectedly during flight, consider the drone's fail-safe behavior (hover or auto-landing) when planning flights.

Affected
Parrot AR.Drone 1
Parrot AR.Drone 2
Estimated exposure
largeon the order of hundreds of thousands of units sold historically (~10^5 devices); the actively used fleet today is plausibly in the tens of thousands (10^4) — The estimate is based on cumulative consumer sales of the AR.Drone line (popular roughly 2010-2014, on the order of several hundred thousand units) rather than internet-exposure scans, since these are Wi-Fi-only consumer drones with no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.