CVE-2023-6950

An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself.
Configurations

No configuration.

History

30 Sep 2024, 10:15

Type Values Removed Values Added
CWE CWE-20 CWE-1286

02 Apr 2024, 14:15

Type Values Removed Values Added
Summary
  • (es) ** EN DISPUTA ** Una vulnerabilidad de validación de entrada incorrecta que afecta el servicio FTP que se ejecuta en el DJI Mavic Mini 3 Pro podría permitir a un atacante crear un paquete malicioso que contenga una ruta mal formada proporcionada el comando FTP TAMAÑO que conduce a un ataque de denegación de servicio del propio servicio FTP.
Summary (en) ** DISPUTED ** An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself. (en) An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself.

02 Apr 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-02 11:15

Updated : 2024-09-30 10:15


NVD link : CVE-2023-6950

Mitre link : CVE-2023-6950

CVE.ORG link : CVE-2023-6950


JSON object : View

Products Affected

No product.

CWE
CWE-1286

Improper Validation of Syntactic Correctness of Input