LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 May 2019 | | Platform | Quiet Systems | | Series | DKSR-M-2019-05 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF MAVSec is the research patch for Kwon’s finding: encrypt MAVLink on ArduPilot/PX4/QGC. It is a prototype, not a vendor close. ### Key judgments 1. **[Assessment — High confidence]** arXiv 1905.00265 first public May 2019 (v2 stamp 4 May). IWCMC 24–28 June is later. 2. **[Assessment — High confidence]** Confirms default MAVLink lacks confidentiality and authentication. 3. **[Inference — Moderate confidence]** Optional research crypto is not a Passport. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. MAVSec: securing MAVLink for ArduPilot/PX4 *Event / publication dates: May 2019 (arXiv 1905.00265). Conference IWCMC 24–28 June 2019 not used for dating.* | Field | Value | | --- | --- | | Component | dependency | | Product | MAVLink as used by ArduPilot and PX4; authors implemented in ArduPilot SITL and QGroundControl | | CVE / advisory | no CVE. Allouch et al. DOI 10.1109/IWCMC.2019.8766667 | | Patch | research prototype, not stock MAVLink | | Exploit status | public writeup | | Taxonomy | CWE-306 (class, problem statement) · CWE-319 (class) · CAPEC-272 · ATT&CK ICS T1692.001 (T0855) · OWASP IoT I2 · I7 · EMB3D TID-406 | **Verified record — [Fact — A1] https://arxiv.org/abs/1905.00265 · https://doi.org/10.1109/iwcmc.2019.8766667** **Exposure.** Same unsigned C2 class. Paper proposes payload encryption. **Intelligence assessment.** [Assessment — High confidence] Paper case, not a CVE. [Inference — Moderate confidence] Later Alias CVEs cite this line of work. **Opportunity.** Do not treat github.com/aniskoubaa/mavsec as evidence a fleet is signed. **LRRK relevance.** Control Fabric. Lab research-crypto vs stock signing. **Confidence.** High. ## Forward indicators 1. Alias RVD/CVE trio (June 2020). 2. Stock MAVLink 2 signing required-by-default (still not this decade’s default). > **Collection integrity.** Dating is arXiv first public. Survey paper (Koubâa IEEE Access June 2019) excluded as not a new disclosure. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>