CVE-2024-33844: Parrot Anafi Firmware

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the drone by sending MAVLink MISSION_COUNT command with a wrong MAV_MISSION_TYPE.

Affected products

  • Parrot Anafi Firmware: version 1.10.4 only

Published 2024-05-03. Last modified 2026-07-09.