CVE-2021-44320
largeUncontrolled Resource Consumption DoS in Parrot AR.Drone 1 and 2
Parrot AR.Drone version 1 and 2 consumer drones lack a suitable mechanism to withstand network flooding, allowing an unauthenticated attacker with access to the drone's Wi-Fi network to disrupt it. By launching IPv4 flood attacks such as SYN flooding or UDP flooding, the attacker exhausts the drone's network resources (CWE-400), degrading or interrupting video streaming and flight control. Only availability is affected, but loss of the control link can interrupt or prematurely end a flight. All operators of first- and second-generation Parrot AR.Drones are potentially affected when an attacker can reach the drone over the network. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS estimates a 0.4% probability of exploitation within 30 days and the issue is not in CISA KEV.
What to do: No patched firmware is identified in the available data, so owners should check for the latest available firmware through Parrot's FreeFlight app and treat the product as effectively end-of-life. Mitigate by operating the drone only on trusted Wi-Fi networks, keeping untrusted devices off or out of range of the drone's network, and ensuring spare control link loss is expected during any local flooding. Defenders should not expect confidentiality or integrity impact, only loss of video streaming and control availability.
| Parrot AR.Drone | Version 1 (all; no fixed version specified in the available data) |
| Parrot AR.Drone 2 | Version 2 (all; no fixed version specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.