# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 May 2019 |
| Platform | Quiet Systems |
| Series | DKSR-M-2019-05 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

MAVSec is the research patch for Kwon’s finding: encrypt MAVLink on ArduPilot/PX4/QGC. It is a prototype, not a vendor close.

### Key judgments

1. **[Assessment — High confidence]** arXiv 1905.00265 first public May 2019 (v2 stamp 4 May). IWCMC 24–28 June is later.
2. **[Assessment — High confidence]** Confirms default MAVLink lacks confidentiality and authentication.
3. **[Inference — Moderate confidence]** Optional research crypto is not a Passport.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. MAVSec: securing MAVLink for ArduPilot/PX4

*Event / publication dates: May 2019 (arXiv 1905.00265). Conference IWCMC 24–28 June 2019 not used for dating.*

| Field | Value |
| --- | --- |
| Component | dependency |
| Product | MAVLink as used by ArduPilot and PX4; authors implemented in ArduPilot SITL and QGroundControl |
| CVE / advisory | no CVE. Allouch et al. DOI 10.1109/IWCMC.2019.8766667 |
| Patch | research prototype, not stock MAVLink |
| Exploit status | public writeup |
| Taxonomy | CWE-306 (class, problem statement) · CWE-319 (class) · CAPEC-272 · ATT&CK ICS T1692.001 (T0855) · OWASP IoT I2 · I7 · EMB3D TID-406 |

**Verified record — [Fact — A1] https://arxiv.org/abs/1905.00265 · https://doi.org/10.1109/iwcmc.2019.8766667**

**Exposure.** Same unsigned C2 class. Paper proposes payload encryption.

**Intelligence assessment.** [Assessment — High confidence] Paper case, not a CVE. [Inference — Moderate confidence] Later Alias CVEs cite this line of work.

**Opportunity.** Do not treat github.com/aniskoubaa/mavsec as evidence a fleet is signed.

**LRRK relevance.** Control Fabric. Lab research-crypto vs stock signing.

**Confidence.** High.

## Forward indicators

1. Alias RVD/CVE trio (June 2020).
2. Stock MAVLink 2 signing required-by-default (still not this decade’s default).

> **Collection integrity.** Dating is arXiv first public. Survey paper (Koubâa IEEE Access June 2019) excluded as not a new disclosure. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
