CVE-2022-29945: High severity DJI Mavic 3 Firmware vulnerability
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29945?
CVE-2022-29945 has a high severity rating due to its potential to expose the physical location of drone operators.
How do I fix CVE-2022-29945?
To mitigate CVE-2022-29945, users should upgrade the affected DJI drone firmware to a version that addresses the vulnerability.
Which DJI drones are affected by CVE-2022-29945?
CVE-2022-29945 affects various DJI models including Mavic 3, Air 2S, and Mini 2 among others produced from 2017 to 2022.
How does CVE-2022-29945 affect user privacy?
CVE-2022-29945 compromises user privacy by broadcasting unencrypted location data, making drone operators vulnerable to tracking.
What is the AeroScope protocol in relation to CVE-2022-29945?
The AeroScope protocol, associated with CVE-2022-29945, is used to communicate the physical location of drones and their operators without encryption.