LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 August 2019 | | Platform | Quiet Systems | | Series | DKSR-M-2019-08 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF Tenable’s ANAFI advisory is public by 23 August 2019. Wi-Fi deauth cuts the link mid-flight; an SDK date field crashes the on-aircraft webserver. Firmware 1.5.0 is the patch. NVD dates are April 2020. ### Key judgments 1. **[Assessment — High confidence]** CVE-2019-3944 / 3945, TRA-2019-22, ANAFI prior to 1.5.0. 2. **[Assessment — High confidence]** First-public month is August 2019 (Wayback), not NVD April 2020. 3. **[Uncertainty]** Exact May 2019 calendar publish day was not found on the live page. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Tenable TRA-2019-22: Parrot ANAFI link cut and SDK crash *Event / publication dates: Wayback-proven public 23 August 2019. Coordinated timeline ends 30 April 2019. NVD 1 April 2020 not used for dating.* | Field | Value | | --- | --- | | Component | firmware | | Product | Parrot ANAFI firmware prior to 1.5.0 | | CVE / advisory | CVE-2019-3944; CVE-2019-3945; TRA-2019-22 | | Patch | available — 1.5.0+ | | Exploit status | public writeup / catalogued | | Taxonomy | ATT&CK ICS T0860 · T0814 · T0858 · OWASP IoT I2 | **Verified record — [Fact — A1] https://www.tenable.com/security/research/tra-2019-22 · https://web.archive.org/web/20190823075008/https://www.tenable.com/security/research/tra-2019-22 · https://nvd.nist.gov/vuln/detail/CVE-2019-3944** **Exposure.** Unauthenticated Wi-Fi deauth severs C2; vendor fallback Smart RTH. SDK path crashes an on-aircraft service. **Intelligence assessment.** [Assessment — High confidence] Cleanest early Western OEM coordinated disclosure in this window. **Opportunity.** Passport ANAFI ≥ 1.5.0. Do not back-date to the NVD month. **LRRK relevance.** Control Fabric. **Confidence.** High on CVE/patch. High that TRA was public by 23 August. ## Forward indicators 1. NVD catalogue April 2020 (index only). 2. ANAFI USA MAVLink CVE (May 2024). > **Collection integrity.** Dating rule is first public, not NVD. CWE not re-fetched this pass — omitted. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>