CVE-2023-6948
Description
A buffer overflow in DJI drone v2_sdk_service allows adjacent attackers to crash the service, causing denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in DJI drone v2_sdk_service allows adjacent attackers to crash the service, causing denial of service.
Vulnerability
Overview The vulnerability is a buffer copy without checking size (CWE-120) in the v2_sdk_service running on port 10000 of certain DJI drone models. The issue exists in the sdk_printf function within the libv2_sdk.so library, used by the dji_vtwo_sdk binary. A crafted payload triggers a missing input size check, leading to a buffer overflow that crashes the service [1].
Attack
Vector An attacker on the same network (adjacent) can send a specially crafted payload to port 10000 to exploit the flaw. The CVSS vector indicates low attack complexity and some privileges are required (PR:L) along with user interaction (UI:R), but the advisory notes that an attacker can cause a denial of service without authentication beyond network access [1].
Impact
Successful exploitation results in a crash of the v2_sdk_service, leading to a denial of service (availability impact). No confidentiality or integrity compromise is reported. Affected models include Mavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30, and Mini 3 Pro on vulnerable firmware versions [1].
Mitigation
Users should upgrade the firmware of affected drones to the latest versions provided by DJI. Specific patched versions are listed in the advisory; for example, Mavic 3 Pro must be updated to v01.01.0300 or later. No workaround is available apart from updating [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6- Range: <=v07.01.10.03
- Range: <=v07.01.0022
- Range: <=v01.00.0620
- Range: <=v01.01.0300
- Range: <=v57.00.01.00
- Range: <=v01.00.0500
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.