CVE-2023-6949 - CVE House
Back to Database
Status published Medium CVE-2023-6949

A Missing Authentication for Critical Function issue affecting the HTTP...

Vulnerability Description

A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6949

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Diego Giubertoni of Nozomi Networks

Affected Vendor

Affected Software

Mini 3 Pro
Vulnerable Versions:
0

Timeline

Official Publish: April 2nd, 2024
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)