CVE-2023-6951: Medium severity DJI Mavic 3 Pro vulnerability

Published Apr 2, 2024
·
Updated

A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform unauthorized interaction with the network services exposed by the drone and to potentially decrypt the Wi-Fi traffic exchanged between the drone and the Android/IOS device of the legitimate user during QuickTransfer mode. Affected models are Mavic 3 Pro until v01.01.0300, Mavic 3 until v01.00.1200, Mavic 3 Classic until v01.00.0500, Mavic 3 Enterprise until v07.01.10.03, Matrice 300 until v57.00.01.00, Matrice M30 until v07.01.0022 and Mini 3 Pro until v01.00.0620.

Affected Software

7 affected components
DJI Mavic 3 Pro<=v01.01.0300
DJI Mavic 3<=v01.00.1200
DJI Mavic 3 Classic<=v01.00.0500
DJI Mavic 3 Enterprise<=v07.01.10.03
DJI Matrice 300<=v57.00.01.00
DJI Matrice M30<=v07.01.0022
DJI Mini 3 Pro<=v01.00.0620

Event History

Apr 2, 2024
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2023-6951?

CVE-2023-6951 is considered a high-severity vulnerability due to the potential for unauthorized access to sensitive Wi-Fi networks.

2

How do I fix CVE-2023-6951?

To fix CVE-2023-6951, update your DJI drone firmware to the latest version provided by the manufacturer.

3

What devices are affected by CVE-2023-6951?

CVE-2023-6951 affects several DJI drone models including Mavic 3, Mini 3 Pro, and Matrice series among others.

4

What kind of attack does CVE-2023-6951 enable?

CVE-2023-6951 enables remote attackers to derive the WPA2 PSK key, allowing unauthorized access to the drone's Wi-Fi network.

5

Is CVE-2023-6951 a widespread issue?

CVE-2023-6951 is specific to certain DJI drones, making its prevalence limited to users of those models.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203