LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 30 June 2013 | | Platform | Quiet Systems | | Series | DKSR-M-2013-06 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF The first NATO CCDCOE / CyCon paper scores military and consumer UAVs on the same cyber-physical factors. Reaper C2, AR.Drone open Wi-Fi, and RQ-170 lost-link are treated as one risk class — assessment, not a new product CVE. ### Key judgments 1. **[Assessment — High confidence]** Hartmann and Steup, CyCon 2013, Tallinn, 4–7 June 2013. NATO CCDCOE / IEEE proceedings. 2. **[Assessment — High confidence]** Risk scheme applied to MQ-9 Reaper and Parrot AR.Drone; RQ-170 discussed. Synthesizes Creech 2011, RQ-170 2011, and AR.Drone — no new defect ID. 3. **[Inference — Moderate confidence]** This is the first in-window NATO-venue statement that the consumer open-Wi-Fi class and military C2 belong on the same tracker. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Hartmann and Steup: UAV cyber-risk assessment *Event / publication dates: 5th International Conference on Cyber Conflict (CyCon 2013), Tallinn, 4–7 June 2013.* | Field | Value | | --- | --- | | Component | software / firmware / hardware | | Product | Risk scheme applied to MQ-9 Reaper and Parrot AR.Drone; RQ-170 discussed | | CVE / advisory | no CVE | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Kim Hartmann, Christoph Steup, “The Vulnerability of UAVs to Cyber Attacks - An Approach to the Risk Assessment,” CyCon 2013. https://ccdcoe.org/uploads/2018/10/26_d3r2s2_hartmann.pdf · https://ieeexplore.ieee.org/document/6568373 · conference dates https://ccdcoe.org/cycon/ **Exposure.** Communications, storage, sensors, fault handling. C2, Sense, and lost-link as scored factors. **Intelligence assessment.** [Assessment — High confidence] First NATO CCDCOE / CyCon paper on this class. [Uncertainty] Assessment paper; no new product bug. **Opportunity.** Do not invent a CWE for a risk scheme. Watch SkyJack (December 2013) as fielded automation of the AR.Drone half. **LRRK relevance.** Watch. Campaign (military and consumer on one sheet). **Confidence.** High on the paper. Moderate as a case. ## Forward indicators 1. SkyJack (December 2013) — automation of the AR.Drone half this paper already scores. 2. A CyCon or ICS follow-on that names a SKU CVE (none in this window). > **Collection integrity.** One assessment paper synthesizing prior cases. No taxonomy (policy/assessment). Not padded. Public sources only. No invented CVEs. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>