Vulnerability Description
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dji | Mavic 2 Firmware | < 01.00.0510 |
| Dji | Mavic 2 | - |
Related Weaknesses (CWE)
References
- http://hacktheplanet.nu/djihax.pdfExploitThird Party Advisory
- http://kth.diva-portal.org/smash/get/diva2:1463784/FULLTEXT01.pdfTechnical DescriptionThird Party Advisory
- https://gist.github.com/viktoredstrom/2f0463ebe7cd786904f229e11386e817Third Party Advisory
- https://www.dji.com/mavic-2Product
- http://hacktheplanet.nu/djihax.pdfExploitThird Party Advisory
- http://kth.diva-portal.org/smash/get/diva2:1463784/FULLTEXT01.pdfTechnical DescriptionThird Party Advisory
- https://gist.github.com/viktoredstrom/2f0463ebe7cd786904f229e11386e817Third Party Advisory
- https://www.dji.com/mavic-2Product
FAQ
What is CVE-2020-29664?
CVE-2020-29664 is a vulnerability with a CVSS score of 7.8 (HIGH). A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.
How severe is CVE-2020-29664?
CVE-2020-29664 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29664?
Check the references section above for vendor advisories and patch information. Affected products include: Dji Mavic 2 Firmware, Dji Mavic 2.