CVE-2021-44320: Parrot AR.Drone vulnerability

Published Sep 4, 2026
·
Updated

Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.

Affected Software

1 affected component
Parrot AR.Drone>=1<=2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Mitigate IPv4 flood (SYN flooding and UDP flooding) by filtering/rate-limiting IPv4 traffic and dropping offending packets at the network (e.g., firewall/ACL) to protect device availability (video streaming and control) on Parrot AR.Drone v1 and v2.

Event History

Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service issue?

Parrot AR.Drone version 1 and version 2 devices are affected. The reported impact is loss of availability for video streaming and drone control.

2

What does an attacker need to do to disrupt the device?

An attacker can perform an IPv4 flood attack against the device. Verified attack methods include SYN flooding and UDP flooding.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203