ZeroHour

CVE-2021-44320

large

Uncontrolled Resource Consumption DoS in Parrot AR.Drone 1 and 2

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
AI analysis

Parrot AR.Drone version 1 and 2 consumer drones lack a suitable mechanism to withstand network flooding, allowing an unauthenticated attacker with access to the drone's Wi-Fi network to disrupt it. By launching IPv4 flood attacks such as SYN flooding or UDP flooding, the attacker exhausts the drone's network resources (CWE-400), degrading or interrupting video streaming and flight control. Only availability is affected, but loss of the control link can interrupt or prematurely end a flight. All operators of first- and second-generation Parrot AR.Drones are potentially affected when an attacker can reach the drone over the network. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS estimates a 0.4% probability of exploitation within 30 days and the issue is not in CISA KEV.

What to do: No patched firmware is identified in the available data, so owners should check for the latest available firmware through Parrot's FreeFlight app and treat the product as effectively end-of-life. Mitigate by operating the drone only on trusted Wi-Fi networks, keeping untrusted devices off or out of range of the drone's network, and ensuring spare control link loss is expected during any local flooding. Defenders should not expect confidentiality or integrity impact, only loss of video streaming and control availability.

Affected
Parrot AR.DroneVersion 1 (all; no fixed version specified in the available data)
Parrot AR.Drone 2Version 2 (all; no fixed version specified in the available data)
Estimated exposure
largeon the order of 100,000s of devices (cumulative lifetime sales of the AR.Drone line); far fewer actively in use and exposed at any given time — Estimated from public reporting that cumulative sales of the Parrot AR.Drone and AR.Drone 2.0 line reached the hundreds of thousands of units, with actual simultaneous exposure much lower because the product line is discontinued and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.