---
id: CVE-2021-44320
title: >-
  Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to
  prevent denial-of-service (DoS) attacks
summary: >-
  Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to
  prevent denial-of-service (DoS) attacks. An attacker can harm the device
  availability (i.e., video streaming and control) by using tool to perform an
  IPv4 flood atta…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:42:20.313'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-44320'
references:
  - url: 'https://github.com/gubertoli/cve/tree/main/CVE-2021-44320'
    label: cve@mitre.org
  - url: 'https://www.researchgate.net/publication/257681090_ARDrone_corruption'
    label: cve@mitre.org
  - url: >-
      https://www.researchgate.net/publication/313177418_The_Impact_of_DoS_Attacks_on_the_ARDrone_20
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00432
epssPercentile: 0.34786
ingestedAt: '2026-09-08T20:10:03.168Z'
---

## Overview

Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
