CVE-2021-44319
largeUnauthenticated Wi-Fi Deauthentication DoS in Parrot AR.Drone 1 and AR.Drone 2
CVE-2021-44319 is a denial-of-service weakness in the Parrot AR.Drone 1 and AR.Drone 2, whose Wi-Fi control link can be knocked offline by a Wi-Fi deauthentication attack. A remote, unauthenticated attacker within wireless range of the drone's Wi-Fi network can trigger the flaw by sending deauthentication frames that force the drone to drop its connection to the controller. The attacker gains an availability-only impact (CVSS 3.1 7.5, A:H): the operator loses control of the drone mid-flight, which can lead to an uncontrolled descent or crash, with no confidentiality or integrity impact. Owners and operators of these discontinued consumer drones are the affected population. Exploitation status is quiet: no public proof-of-concept is known, it is not in CISA KEV, and EPSS assigns a 0.5% probability of exploitation in the next 30 days, although deauthentication tooling is trivially available to any attacker with basic wireless equipment.
What to do: No patched firmware is documented in the available data; check Parrot's support channels for the latest AR.Drone 1/2 firmware before flying. Because deauthentication frames are unauthenticated 802.11 management frames that encryption settings alone cannot block, mitigate operationally by flying away from dense or congested 2.4 GHz Wi-Fi environments and treating mid-flight disconnects as the primary risk. If a controller link drops unexpectedly during flight, consider the drone's fail-safe behavior (hover or auto-landing) when planning flights.
| Parrot AR.Drone 1 | — |
| Parrot AR.Drone 2 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.