Parrot's vulnerability footprint centers on a small line of consumer and commercial unmanned-aircraft systems, including the Anafi and Bebop drone platforms and their associated firmware. The observed disclosures cluster around resource-management and configuration weaknesses—unthrottled resource allocation, improper resource cleanup, and incorrect default permissions—typical of embedded systems where resource constraints and secure-by-default configuration practices are critical. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Parrot over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3944HIGH Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight. | Apr 1, 2020 | 7.5 | 25 | NO | NO |
CVE-2024-33844HIGH The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the dr | May 3, 2024 | 7.5 | 24 | NO | NO |
CVE-2019-3945HIGH Web server running on Parrot ANAFI can be crashed due to the SDK command "Common_CurrentDateTime" being sent to control service with larger than expected date length. | Apr 1, 2020 | 7.5 | 24 | NO | NO |
CVE-2022-46416MEDIUM Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to | Mar 27, 2023 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Parrot.
Media articles that mention a CVE ID that affects a product developed by Parrot — matched by CVE ID, not by vendor name.