CVE-2021-44320: Parrot AR.Drone vulnerability
Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate IPv4 flood (SYN flooding and UDP flooding) by filtering/rate-limiting IPv4 traffic and dropping offending packets at the network (e.g., firewall/ACL) to protect device availability (video streaming and control) on Parrot AR.Drone v1 and v2.
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Parrot AR.Drone version 1 and version 2 devices are affected. The reported impact is loss of availability for video streaming and drone control.
What does an attacker need to do to disrupt the device?
An attacker can perform an IPv4 flood attack against the device. Verified attack methods include SYN flooding and UDP flooding.