perception
PERCEPTION_PRIVACY
Vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE CPATH-2026-0020 · DRONE AV
PERCEPTION_PRIVACY perception · Evidence EV:2 (report-backed) · Liveness PATCH_AVAILABLE | CPATH ID | CPATH-2026-0020 |
| CVE(s) | CVE-2023-6951 |
| Device / class | DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951) (DRONE AV) |
| Vendor | DJI |
| Dominant consequence | PERCEPTION_PRIVACY (perception) |
| Paths verdict | CRITICAL (worst of 2 paths) |
| Published baseline | v3.1 6.6 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N · Nozomi Networks via NVD |
| Baseline relationship | ▼ Paths higher |
| Consequence dimension(s) | #1 #2 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | high |
Consequence Paths
perception
PERCEPTION_PRIVACYCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE perception
DATA_PRIVACYCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE CFSE Consequence Paths assesses DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is exposure of sensor or biometric data.
DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951). Reported attack vector: Adjacent network (drone Wi-Fi range).
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_PRIVACY → CRITICALCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=CRITICAL · AT=ELEVATED → base CRITICAL · caps privacy-only cap → assessed CRITICAL.
DATA_PRIVACY → HIGHCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=HIGH · AT=ELEVATED → base HIGH · caps privacy-only cap → assessed HIGH.
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N — Nozomi Networks via NVDThe published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0020 (“DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951)”), paths.cfse.ai/CPATH-2026-0020 (published 2026-06-03).