LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 August 2022 | | Platform | Quiet Systems | | Series | DKSR-M-2022-08 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF Sathaye et al. at USENIX Security 2022 is the in-window citation that COTS DJI and Autel remain GPS-spoofable. Civil GNSS is still unauthenticated. ### Key judgments 1. **[Assessment — High confidence]** Chamber OTA on current DJI/Autel stacks updates the Humphreys 2012 citation without becoming a CVE. 2. **[Assessment — High confidence]** Precise takeover is non-trivial and needs real-time signal control; nuisance spoof is not the same claim. 3. **[Inference — Moderate confidence]** OSNMA (2025) will appear later as a mitigation field, not a close of this class. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Sathaye et al.: GPS spoof / takeover on COTS UAVs *Event / publication dates: 10–12 August 2022, 31st USENIX Security Symposium, Boston* | Field | Value | | --- | --- | | Component | hardware | | Product | COTS UAVs from DJI and Autel (paper evaluation set) | | CVE / advisory | no CVE | | Patch | not applicable (civil GNSS property) | | Exploit status | public writeup; RtGSG released to researchers | | Taxonomy | CWE-345 (class) · CAPEC-148 · OWASP IoT I7 | **Verified record — [Fact — A1] Sathaye, Strohmeier, Lenders, Ranganathan, USENIX Security 2022. https://www.usenix.org/conference/usenixsecurity22/presentation/sathaye · https://www.usenix.org/system/files/sec22-sathaye.pdf** **Exposure.** Unauthenticated civil GPS is navigation-state capture. Sense collapses Move. **Intelligence assessment.** [Assessment — High confidence] Standard in-window GPS-takeover citation. [Inference — Moderate confidence] Complete stable takeover ≠ a cheap spoof. **Opportunity.** Passport GNSS authentication as an evidenced field. Lab takeover vs nuisance spoof as different claims. **LRRK relevance.** Sense-Move-Act. KAT from RF to navigation state. **Confidence.** High. ## Forward indicators 1. Galileo OSNMA operational (filed later as DKSR-M-2025-07). 2. A u-blox or OEM CVE that actually cites UAV impact (none in this month). > **Collection integrity.** One verified paper. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>