CVE-2023-6949: Medium severity DJI Mavic Mini 3 Pro vulnerability
A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6949?
CVE-2023-6949 is rated as a critical vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2023-6949?
To mitigate CVE-2023-6949, it is recommended to disable the HTTP service or restrict access to authorized users only.
What systems are affected by CVE-2023-6949?
CVE-2023-6949 affects the HTTP service on the DJI Mavic Mini 3 Pro drone.
What type of vulnerability is CVE-2023-6949?
CVE-2023-6949 is classified as a Missing Authentication for Critical Function vulnerability.
What could an attacker do with CVE-2023-6949?
An attacker could enumerate and download videos and pictures from the drone's internal or external memory without any authentication.