CVE-2020-10281 describes an information disclosure vulnerability within the Micro Air Vehicle Link (MAVLink) protocol, impacting dronecode micro_air_vehicle_link products. Due to the protocol's unencrypted design for efficiency, a remote attacker with access to the communication medium can intercept sensitive information. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and no user interaction required, leading to a high impact on confidentiality. While the EPSS score is low and there is no evidence of active exploitation, public exploit code, or significant community discussion, the inherent design flaw makes it a notable risk for MAVLink deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:dronecode:micro_air_vehicle_link:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.