« Volver al listado

CVE-2023-6951

Estado: AplazadaMedia (6.6)—

A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform unauthorized interaction with the network services exposed by the drone and to potentially decrypt the Wi-Fi traffic exchanged between the drone and the Android/IOS device of the legitimate user during QuickTransfer mode. Affected models are Mavic 3 Pro until v01.01.0300, Mavic 3 until v01.00.1200, Mavic 3 Classic until v01.00.0500, Mavic 3 Enterprise until v07.01.10.03, Matrice 300 until v57.00.01.00, Matrice M30 until v07.01.0022 and Mini 3 Pro until v01.00.0620.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6951",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-6951",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-02T18:42:46.556534Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "prodsec@nozominetworks.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "prodsec@nozominetworks.com",
      "affectedData": [
        {
          "vendor": "DJI",
          "product": "Mavic 3 Pro",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "01.01.0300",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "DJI",
          "product": "Mavic 3",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "01.00.1200",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "DJI",
          "product": "Mavic 3 Classic",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "01.00.0500",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "DJI",
          "product": "Mavic 3 Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.01.10.03",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "DJI",
          "product": "Matrice 300",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "57.00.01.00",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "DJI",
          "product": "Matrice M30",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "07.01.0022",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "DJI",
          "product": "Mini 3 Pro",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "01.00.0620",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-02T11:15:51.417",
  "references": [
    {
      "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-6951/",
      "source": "prodsec@nozominetworks.com"
    },
    {
      "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-6951/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "prodsec@nozominetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-334"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the attacker to perform unauthorized interaction with the network services exposed by the drone and to potentially decrypt the Wi-Fi traffic exchanged between the drone and the Android/IOS device of the legitimate user during QuickTransfer mode. Affected models are Mavic 3 Pro until v01.01.0300, Mavic 3 until v01.00.1200, Mavic 3 Classic until v01.00.0500, Mavic 3 Enterprise until v07.01.10.03, Matrice 300 until v57.00.01.00, Matrice M30 until v07.01.0022 and Mini 3 Pro until v01.00.0620."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de uso de credenciales débiles que afecta a la red Wi-Fi generada por un conjunto de drones DJI podría permitir que un atacante remoto obtenga la clave WPA2 PSK y se autentique sin permiso en la red Wi-Fi del dron. Esto, a su vez, permite al atacante realizar una interacción no autorizada con los servicios de red expuestos por el dron y potencialmente descifrar el tráfico Wi-Fi intercambiado entre el dron y el dispositivo Android/IOS del usuario legítimo durante el modo QuickTransfer. Los modelos afectados son Mavic 3 Pro hasta v01.01.0300, Mavic 3 hasta v01.00.1200, Mavic 3 Classic hasta v01.00.0500, Mavic 3 Enterprise hasta v07.01.10.03, Matrice 300 hasta v57.00.01.00, Matrice M30 hasta v07. 01.0022 y Mini 3 Pro hasta v01.00.0620."
    }
  ],
  "lastModified": "2026-06-17T06:51:45.237",
  "sourceIdentifier": "prodsec@nozominetworks.com"
}