← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2019-08.md
Imported-content SHA-256
58e3c45d10ced1e337e7a51633ab079b1e1b901a5045b9a06461cddda47c9a16
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 August 2019 |
| Platform | Quiet Systems |
| Series | DKSR-M-2019-08 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

Tenable’s ANAFI advisory is public by 23 August 2019. Wi-Fi deauth cuts the link mid-flight; an SDK date field crashes the on-aircraft webserver. Firmware 1.5.0 is the patch. NVD dates are April 2020.

### Key judgments

1. **[Assessment — High confidence]** CVE-2019-3944 / 3945, TRA-2019-22, ANAFI prior to 1.5.0.
2. **[Assessment — High confidence]** First-public month is August 2019 (Wayback), not NVD April 2020.
3. **[Uncertainty]** Exact May 2019 calendar publish day was not found on the live page.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Tenable TRA-2019-22: Parrot ANAFI link cut and SDK crash

*Event / publication dates: Wayback-proven public 23 August 2019. Coordinated timeline ends 30 April 2019. NVD 1 April 2020 not used for dating.*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Parrot ANAFI firmware prior to 1.5.0 |
| CVE / advisory | CVE-2019-3944; CVE-2019-3945; TRA-2019-22 |
| Patch | available — 1.5.0+ |
| Exploit status | public writeup / catalogued |
| Taxonomy | ATT&CK ICS T0860 · T0814 · T0858 · OWASP IoT I2 |

**Verified record — [Fact — A1] https://www.tenable.com/security/research/tra-2019-22 · https://web.archive.org/web/20190823075008/https://www.tenable.com/security/research/tra-2019-22 · https://nvd.nist.gov/vuln/detail/CVE-2019-3944**

**Exposure.** Unauthenticated Wi-Fi deauth severs C2; vendor fallback Smart RTH. SDK path crashes an on-aircraft service.

**Intelligence assessment.** [Assessment — High confidence] Cleanest early Western OEM coordinated disclosure in this window.

**Opportunity.** Passport ANAFI ≥ 1.5.0. Do not back-date to the NVD month.

**LRRK relevance.** Control Fabric.

**Confidence.** High on CVE/patch. High that TRA was public by 23 August.

## Forward indicators

1. NVD catalogue April 2020 (index only).
2. ANAFI USA MAVLink CVE (May 2024).

> **Collection integrity.** Dating rule is first public, not NVD. CWE not re-fetched this pass — omitted. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>