CVE-2025-71409

ATN-B1 · CPDLC

The ATN-B1 CPDLC protocol lacks authentication for data link messages, allowing rogue ground stations to inject misleading clearances and cause pilot confusion.

Executive summary

A critical lack of authentication in the ATN-B1 CPDLC protocol allows for the injection of malicious messages, posing a significant risk to aviation communication integrity.

Vulnerability

This is a missing authentication vulnerability (CWE-306) affecting Very High Frequency Data Link communications. The lack of message origin verification allows unauthorized entities to inject messages, which can be interpreted by flight crews as legitimate instructions.

Business impact

The integrity of air traffic communication is paramount for flight safety. The ability for an attacker to inject misleading clearances could lead to severe operational hazards, potential accidents, and a complete loss of trust in the communication system. The CVSS score of 7.1 underscores the high risk posed to safety-critical infrastructure.

Remediation

Immediate Action: Follow guidance provided in CISA advisory ICSA-26-219-01, as a direct software patch may not be available for all legacy implementations.

Proactive Monitoring: Monitor for anomalous communication patterns or unexpected message sequences that deviate from standard ground station behavior.

Compensating Controls: Implement secondary verification procedures for all received clearances and utilize physical layer monitoring where feasible to detect unauthorized signal sources.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the safety-critical nature of the affected technology, immediate attention to the CISA advisory is required. Stakeholders must implement the recommended compensating controls to mitigate the risk of message injection until structural protocol changes can be implemented.