CVE Feed

    Dashboard / CVE / CVE-2023-51456

    CVE-2023-51456

    A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a crafted payload due to a missing input sanity check in the v2_pack_array_to_msg function implemented in the libv2_sdk.so library imported by the v2_sdk_service binary implementing the service, potentially leading to a memory information leak or an arbitrary code execution. Affected models are Mavic 3 Pro until v01.01.0300, Mavic 3 until v01.00.1200, Mavic 3 Classic until v01.00.0500, Mavic 3 Enterprise until v07.01.10.03, Matrice 300 until v57.00.01.00, Matrice M30 until v07.01.0022 and Mini 3 Pro until v01.00.0620.

    Published:Apr 2, 2024
    Last Modified:Apr 15, 2026
    EPS:Apr 2, 2024
    EPSS Score:0.00089
    CVSS Score:6.8

    Affected Products

    Vendor
    Dji
    Product
    Matrice 300 Firmware
    Vendor
    Dji
    Product
    Matrice M30 Firmware
    Vendor
    Dji
    Product
    Mavic 3 Firmware
    Vendor
    Dji
    Product
    Mavic 3 Pro Firmware
    Vendor
    Dji
    Product
    Mini 3 Pro Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High