Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.
History

Mon, 18 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Holy Stone Remote Id Module
Holy Stone Remote Id Module holy Stone Remote Id Module
Weaknesses CWE-125
CPEs cpe:2.3:a:holy_stone_remote_id_module:holy_stone_remote_id_module:*:*:*:*:*:*:*:*
Vendors & Products Holy Stone Remote Id Module
Holy Stone Remote Id Module holy Stone Remote Id Module
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 17 Nov 2024 04:30:00 +0000

Type Values Removed Values Added
Description Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-18T16:47:10.822Z

Reserved: 2024-11-17T00:00:00

Link: CVE-2024-52876

cve-icon Vulnrichment

Updated: 2024-11-18T16:47:04.686Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-17T05:15:04.760

Modified: 2024-11-18T17:35:08.900

Link: CVE-2024-52876

cve-icon Redhat

No data.