7.5
CVE-2022-29945
- EPSS 0.22%
- Veröffentlicht 29.04.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:00:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dji ≫ Mavic 3 Firmware Version-
Dji ≫ Rc Pro Firmware Version-
Dji ≫ Air 2s Firmware Version-
Dji ≫ Air 2 Firmware Version-
Dji ≫ Mini 2 Firmware Version-
Dji ≫ Mini Se Firmware Version-
Dji ≫ Fpv Firmware Version-
Dji ≫ Fhantom 4 Pro Firmware Version-
Dji ≫ Inspire 2 Firmware Version-
Dji ≫ Zenmuse X7 Firmware Version-
Dji ≫ Zenmuse X5s Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.443 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| cve@mitre.org | 4 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.