LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 30 June 2016 | | Platform | Quiet Systems | | Series | DKSR-M-2016-06 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF First public named-university disclosure that Bebop’s ARDiscovery path can force mid-flight rotor stop or emergency land. Move/Act, not just video theft. No CVE. ### Key judgments 1. **[Assessment — High confidence]** 8 June 2016 (JHU Hub / ScienceDaily / phys.org). Live Science 10 June. Forbes 13 June. 2. **[Assessment — High confidence]** Product: Parrot Bebop 1. University sent a Vulnerability Disclosure Package “early this year”; JHU said Parrot had not responded by end of May 2016. 3. **[Uncertainty]** Later MILCOM paper calls them “three zero-day vulnerabilities.” No versioned Parrot advisory found in 2016. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Hooper / Watkins et al.: Parrot Bebop ARDiscovery / Wi-Fi *Event / publication dates: 8 June 2016 (JHU Hub / ScienceDaily / phys.org)* | Field | Value | | --- | --- | | Component | firmware | | Product | Parrot Bebop 1 (ARDiscovery over the aircraft Wi-Fi AP) | | CVE / advisory | no CVE | | Patch | none found as a versioned Parrot advisory in 2016 | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 | **Verified record — [Fact — B1] JHU Hub 8 Jun 2016 https://hub.jhu.edu/2016/06/08/hacking-drones-security-flaws/ · ScienceDaily https://www.sciencedaily.com/releases/2016/06/160608113252.htm · Live Science 10 Jun 2016 https://www.livescience.com/55046-how-can-drones-be-hacked.html** **Exposure.** Connection-handling DoS, ARDiscovery buffer overflow, ARP cache poisoning of the GCS link. Mid-flight rotor stop or emergency land. **Intelligence assessment.** [Assessment — High confidence] 8 June 2016 as first public day and Bebop as the target. High that no CVE was assigned. **Opportunity.** Date MILCOM (November) as the archival paper, not a second vuln. **LRRK relevance.** Control Fabric. Sense-Move-Act. **Confidence.** High. ## Forward indicators 1. Hooper et al. MILCOM paper (November 2016). > **Collection integrity.** One university disclosure. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>