CISA published an ICS advisory detailing five vulnerabilities in the CPDLC over ATN-B1 aviation data link protocol. The protocol relies on legacy clear-text, unauthenticated VHF radio frequency links, enabling rogue ground stations to inject false CPDLC messages, terminate sessions, and trigger denial-of-service conditions. No patches or mitigations are available. The vulnerabilities require high attack complexity and specific conditions, making exploitation unlikely outside a lab environment, but successful exploitation could degrade operational safety margins in air traffic management.
Aviation ICS
1 post
CPDLC over ATN-B1 Vulnerabilities (CVE-2025-71409, CVE-2025-71410, CVE-2025-71411 +2 more)