« Volver al listado

CVE-2023-6950

Estado: AplazadaBaja (3)—

An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6950",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "prodsec@nozominetworks.com"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-6950",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-07T17:50:04.755910Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "prodsec@nozominetworks.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "prodsec@nozominetworks.com",
      "affectedData": [
        {
          "vendor": "DJI",
          "product": "Mini 3 Pro",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "01.00.1200",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-02T11:15:51.243",
  "references": [
    {
      "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-6950/",
      "source": "prodsec@nozominetworks.com"
    },
    {
      "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-6950/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "prodsec@nozominetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1286"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself."
    },
    {
      "lang": "es",
      "value": "** EN DISPUTA ** Una vulnerabilidad de validación de entrada incorrecta que afecta el servicio FTP que se ejecuta en el DJI Mavic Mini 3 Pro podría permitir a un atacante crear un paquete malicioso que contenga una ruta mal formada proporcionada el comando FTP TAMAÑO que conduce a un ataque de denegación de servicio del propio servicio FTP."
    }
  ],
  "lastModified": "2026-06-17T06:51:45.127",
  "sourceIdentifier": "prodsec@nozominetworks.com"
}