CVE-2022-46416

CRITICAL

Parrot Bebop 4.7.1 - Denial of Service via DHCP IP Address Pool Exhaustion

Title source: llm
STIX 2.1

Description

Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to connect to the device's internal Wi-Fi network (e.g., by guessing the password). Then, the attacker would need to send many DHCP request packets.

Scores

CVSS v3 9.1
EPSS 0.0088
EPSS Percentile 54.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (1)
parrot/bebop_firmware 4.7.1
Published Mar 27, 2023
Tracked Since Feb 18, 2026