Vulnerability Description
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dji | Mavic 3 Firmware | - |
| Dji | Mavic 3 | - |
| Dji | Rc Pro Firmware | - |
| Dji | Rc Pro | - |
| Dji | Air 2S Firmware | - |
| Dji | Air 2S | - |
| Dji | Air 2 Firmware | - |
| Dji | Air 2 | - |
| Dji | Mini 2 Firmware | - |
| Dji | Mini 2 | - |
| Dji | Mini Se Firmware | - |
| Dji | Mini Se | - |
| Dji | Fpv Firmware | - |
| Dji | Fpv | - |
| Dji | Fhantom 4 Pro Firmware | - |
| Dji | Fhantom 4 Pro | - |
| Dji | Inspire 2 Firmware | - |
| Dji | Inspire 2 | - |
| Dji | Zenmuse X7 Firmware | - |
| Dji | Zenmuse X7 | - |
Related Weaknesses (CWE)
References
- https://twitter.com/StarFire2258/status/1519767091829637120Third Party Advisory
- https://twitter.com/d0tslash/status/1519774807776284672Third Party Advisory
- https://www.theverge.com/2022/4/28/23046916/dji-aeroscope-signals-not-encrypted-Press/Media CoverageThird Party Advisory
- https://twitter.com/StarFire2258/status/1519767091829637120Third Party Advisory
- https://twitter.com/d0tslash/status/1519774807776284672Third Party Advisory
- https://www.theverge.com/2022/4/28/23046916/dji-aeroscope-signals-not-encrypted-Press/Media CoverageThird Party Advisory
FAQ
What is CVE-2022-29945?
CVE-2022-29945 is a vulnerability with a CVSS score of 4.0 (MEDIUM). DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
How severe is CVE-2022-29945?
CVE-2022-29945 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29945?
Check the references section above for vendor advisories and patch information. Affected products include: Dji Mavic 3 Firmware, Dji Mavic 3, Dji Rc Pro Firmware, Dji Rc Pro, Dji Air 2S Firmware.