ID

VAR-202405-1101


CVE

CVE-2024-33844


TITLE

Parrot  of  ANAFI  Firmware vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2024-003310

DESCRIPTION

The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the drone by sending MAVLink MISSION_COUNT command with a wrong MAV_MISSION_TYPE. Parrot of ANAFI There are unspecified vulnerabilities in the firmware.Service operation interruption (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2024-33844 // JVNDB: JVNDB-2024-003310

AFFECTED PRODUCTS

vendor:parrotmodel:anafiscope:eqversion:1.10.4

Trust: 1.0

vendor:parrotmodel:anafiscope:eqversion:anafi firmware 1.10.4

Trust: 0.8

vendor:parrotmodel:anafiscope:eqversion: -

Trust: 0.8

vendor:parrotmodel:anafiscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2024-003310 // NVD: CVE-2024-33844

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-33844
value: HIGH

Trust: 1.0

NVD: CVE-2024-33844
value: HIGH

Trust: 0.8

nvd@nist.gov: CVE-2024-33844
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2024-33844
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2024-003310 // NVD: CVE-2024-33844

PROBLEMTYPE DATA

problemtype:CWE-404

Trust: 1.0

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-003310 // NVD: CVE-2024-33844

EXTERNAL IDS

db:NVDid:CVE-2024-33844

Trust: 2.6

db:JVNDBid:JVNDB-2024-003310

Trust: 0.8

sources: JVNDB: JVNDB-2024-003310 // NVD: CVE-2024-33844

REFERENCES

url:http://anafi.com

Trust: 1.8

url:https://forum.developer.parrot.com/t/cve-2024-33844-bugs-in-anafi-thermal-usa-firmware/22501

Trust: 1.8

url:https://forum.developer.parrot.com/t/cve-2024-33844-bugs-in-anafi-thermal-usa-firmware/22501/1

Trust: 1.8

url:http://nvd-cwe-other.com

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-33844

Trust: 0.8

sources: JVNDB: JVNDB-2024-003310 // NVD: CVE-2024-33844

SOURCES

db:JVNDBid:JVNDB-2024-003310
db:NVDid:CVE-2024-33844

LAST UPDATE DATE

2024-08-14T15:31:32.659000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2024-003310date:2024-06-11T08:36:00
db:NVDid:CVE-2024-33844date:2024-08-06T15:35:14.480

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2024-003310date:2024-06-11T00:00:00
db:NVDid:CVE-2024-33844date:2024-05-03T15:15:08.157