CVE-2020-10283: RVD#3317: MAVLink version handshaking allows for an attacker to bypass authentication

Published Aug 20, 2020
·
Updated

The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibility, GCS and autopilot negotiate the version via the AUTOPILOTVERSION message. Since this negotiation depends on the answer, an attacker may craft packages in a way that hints the autopilot to adopt version 1.0 of MAVLink for the communication. Given the lack of authentication capabilities in such version of MAVLink (refer to CVE-2020-10282), attackers may use this method to bypass authentication capabilities and interact with the autopilot directly.

Affected Software

1 affected component
Dronecode Micro Air Vehicle Link=1.0.0

Event History

Aug 20, 2020
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2020-10283?

CVE-2020-10283 is a vulnerability in the Micro Air Vehicle Link (MAVLink) protocol that allows unauthorized access due to a version negotiation issue.

2

How severe is CVE-2020-10283?

CVE-2020-10283 has a severity rating of 9.8 (critical).

3

What software is affected by CVE-2020-10283?

The affected software is Dronecode Micro Air Vehicle Link (MAVLink) version 1.0.0.

4

How can I fix CVE-2020-10283?

To fix CVE-2020-10283, update the Dronecode Micro Air Vehicle Link (MAVLink) software to a version that includes a patch for the vulnerability.

5

Where can I find more information about CVE-2020-10283?

You can find more information about CVE-2020-10283 at the following reference: [GitHub](https://github.com/aliasrobotics/RVD/issues/3316)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203