# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 30 June 2020 |
| Platform | Quiet Systems |
| Series | DKSR-M-2020-06 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

Alias Robotics files the first CVEs for MAVLink cleartext, missing authentication, and v2→v1 downgrade. NVD publishes in July and August. Dating is the RVD day.

### Key judgments

1. **[Assessment — High confidence]** RVD#3315–3317 created 30 June 2020. CVE-2020-10281 (CWE-319), 10282 (CWE-306), 10283 (CWE-288).
2. **[Assessment — High confidence]** This is Kwon/MAVSec as inventory, including the first signed-but-broken ID.
3. **[Uncertainty]** ArduPilot maintainers disputed applicability. Current-build downgrade not re-tested.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Alias RVD#3315–3317: MAVLink cleartext, no auth, downgrade

*Event / publication dates: 30 June 2020 (RVD created). NVD 10281/10282 on 3 July; 10283 on 20 August — later, not used for dating.*

| Field | Value |
| --- | --- |
| Component | dependency |
| Product | Dronecode MAVLink 1.0 / 2.0 as used by PX4 and ArduPilot (Alias labels) |
| CVE / advisory | CVE-2020-10281; CVE-2020-10282; CVE-2020-10283. CNA: Alias Robotics |
| Patch | none as a protocol RFC. Mitigation: encrypt bearer; MAVLink 2 signing; refuse v1 |
| Exploit status | catalogued. Alias: exploitation “not available.” Not KEV |
| Taxonomy | CWE-319 (NVD, 10281) · CWE-306 (NVD, 10282) · CWE-288 (CNA, 10283) · CAPEC-272 · CAPEC-620 · ATT&CK ICS T1692.001 (T0855) · OWASP IoT I2 · I7 · EMB3D TID-406 |

**Verified record — [Fact — A1] https://github.com/aliasrobotics/RVD/issues/3316 · https://nvd.nist.gov/vuln/detail/CVE-2020-10282 · https://nvd.nist.gov/vuln/detail/CVE-2020-10283**

**Exposure.** Whoever can speak on the bearer owns the vehicle, and signing is optional and downgradeable.

**Intelligence assessment.** [Assessment — High confidence] First formal IDs. [Uncertainty] Implementation vs design-choice dispute is public and travels with the IDs.

**Opportunity.** Passport “signing required and v1 refused.” Do not split these three across July/August NVD months.

**LRRK relevance.** Control Fabric.

**Confidence.** High on dates and CVE text. Moderate on current-build applicability.

## Forward indicators

1. NVD catalogue July/August 2020 (index only).
2. CISA ICSA-26-090-02 (March 2026) — same CWE-306, now ICS.

> **Collection integrity.** First-public is RVD 30 June. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
