LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 30 June 2020 | | Platform | Quiet Systems | | Series | DKSR-M-2020-06 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF Alias Robotics files the first CVEs for MAVLink cleartext, missing authentication, and v2→v1 downgrade. NVD publishes in July and August. Dating is the RVD day. ### Key judgments 1. **[Assessment — High confidence]** RVD#3315–3317 created 30 June 2020. CVE-2020-10281 (CWE-319), 10282 (CWE-306), 10283 (CWE-288). 2. **[Assessment — High confidence]** This is Kwon/MAVSec as inventory, including the first signed-but-broken ID. 3. **[Uncertainty]** ArduPilot maintainers disputed applicability. Current-build downgrade not re-tested. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Alias RVD#3315–3317: MAVLink cleartext, no auth, downgrade *Event / publication dates: 30 June 2020 (RVD created). NVD 10281/10282 on 3 July; 10283 on 20 August — later, not used for dating.* | Field | Value | | --- | --- | | Component | dependency | | Product | Dronecode MAVLink 1.0 / 2.0 as used by PX4 and ArduPilot (Alias labels) | | CVE / advisory | CVE-2020-10281; CVE-2020-10282; CVE-2020-10283. CNA: Alias Robotics | | Patch | none as a protocol RFC. Mitigation: encrypt bearer; MAVLink 2 signing; refuse v1 | | Exploit status | catalogued. Alias: exploitation “not available.” Not KEV | | Taxonomy | CWE-319 (NVD, 10281) · CWE-306 (NVD, 10282) · CWE-288 (CNA, 10283) · CAPEC-272 · CAPEC-620 · ATT&CK ICS T1692.001 (T0855) · OWASP IoT I2 · I7 · EMB3D TID-406 | **Verified record — [Fact — A1] https://github.com/aliasrobotics/RVD/issues/3316 · https://nvd.nist.gov/vuln/detail/CVE-2020-10282 · https://nvd.nist.gov/vuln/detail/CVE-2020-10283** **Exposure.** Whoever can speak on the bearer owns the vehicle, and signing is optional and downgradeable. **Intelligence assessment.** [Assessment — High confidence] First formal IDs. [Uncertainty] Implementation vs design-choice dispute is public and travels with the IDs. **Opportunity.** Passport “signing required and v1 refused.” Do not split these three across July/August NVD months. **LRRK relevance.** Control Fabric. **Confidence.** High on dates and CVE text. Moderate on current-build applicability. ## Forward indicators 1. NVD catalogue July/August 2020 (index only). 2. CISA ICSA-26-090-02 (March 2026) — same CWE-306, now ICS. > **Collection integrity.** First-public is RVD 30 June. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>