A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dji
Dji mini 3 Pro Firmware |
|
CPEs | cpe:2.3:o:dji:mini_3_pro_firmware:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dji
Dji mini 3 Pro Firmware |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2025-02-13T17:27:01.071Z
Reserved: 2023-12-19T15:38:35.001Z
Link: CVE-2023-6949

Updated: 2024-08-02T08:42:08.539Z

Status : Awaiting Analysis
Published: 2024-04-02T11:15:51.070
Modified: 2024-11-21T08:44:54.107
Link: CVE-2023-6949

No data.