CVE-2021-44319
Parrot · AR.Drone
Parrot AR.Drone 1 and 2 are vulnerable to a remote, unauthenticated Wi-Fi deauthentication attack, allowing an attacker to forcibly disconnect the drone from its controller during flight.
Executive summary
The Parrot AR.Drone 1 and 2 platforms are susceptible to a critical denial of service vulnerability that allows remote, unauthenticated attackers to hijack control by severing the wireless link.
Vulnerability
The device is vulnerable to a Wi-Fi deauthentication attack, enabling an unauthenticated attacker within range to send malicious management frames to drop the connection between the drone and the pilot.
Business impact
A successful exploit results in a complete loss of command and control over the drone during operation. Given the CVSS score of 7.5, this high-severity vulnerability poses significant physical safety risks and potential for equipment destruction, as the aircraft may become unresponsive or crash upon losing the controller link.
Remediation
Immediate Action: There is no known firmware patch available for these legacy devices; operators should restrict flight operations to secure or signal-controlled environments to minimize exposure.
Proactive Monitoring: Monitor the wireless spectrum for unusual deauthentication frame patterns or unauthorized signal interference in the vicinity of drone operations.
Compensating Controls: Utilize physical security measures to limit access to the wireless range of the drone and consider implementing frequency hopping or shielded communication protocols if the operational environment allows.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the researcher's GitHub repository linked in the CVE record.
Analyst recommendation
Due to the safety-critical nature of this vulnerability and the lack of a vendor-provided patch, users should exercise extreme caution when operating these devices in public spaces. Organizations relying on Parrot AR.Drone hardware for professional or security applications should evaluate migrating to modern, authenticated drone platforms that support encrypted communication channels to eliminate this risk.
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written