Vulnerability Description
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dronecode | Px4 Drone Autopilot | <= 1.11.3 |
| Yuneec | Mantis Q Firmware | - |
| Yuneec | Mantis Q | - |
Related Weaknesses (CWE)
References
- https://gist.github.com/swkim101/f473b9a60e6d4635268402a2cd2025acExploitThird Party Advisory
- https://github.com/PX4/PX4-Autopilot/issues/17062ExploitIssue Tracking
- https://github.com/PX4/PX4-Autopilot/pull/17264/commits/555f900cf52c0057e4c429ffPatch
- https://github.com/apache/incubator-nuttx-apps/pull/647/commits/2fc1157f8585acc3Patch
- https://github.com/apache/incubator-nuttx/pull/3292/commits/016873788280ca815ba8Patch
- https://nuttx.apache.org/Product
- https://nuttx.apache.org/docs/latest/applications/nsh/commands.html#access-memorProduct
- https://www.st.com/resource/en/application_note/dm00493651-introduction-to-stm32Product
- https://gist.github.com/swkim101/f473b9a60e6d4635268402a2cd2025acExploitThird Party Advisory
- https://github.com/PX4/PX4-Autopilot/issues/17062ExploitIssue Tracking
- https://github.com/PX4/PX4-Autopilot/pull/17264/commits/555f900cf52c0057e4c429ffPatch
- https://github.com/apache/incubator-nuttx-apps/pull/647/commits/2fc1157f8585acc3Patch
- https://github.com/apache/incubator-nuttx/pull/3292/commits/016873788280ca815ba8Patch
- https://nuttx.apache.org/Product
- https://nuttx.apache.org/docs/latest/applications/nsh/commands.html#access-memorProduct
FAQ
What is CVE-2021-34125?
CVE-2021-34125 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.
How severe is CVE-2021-34125?
CVE-2021-34125 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-34125?
Check the references section above for vendor advisories and patch information. Affected products include: Dronecode Px4 Drone Autopilot, Yuneec Mantis Q Firmware, Yuneec Mantis Q.