CVE-2025-71412

ATN-B1 · CPDLC

A vulnerability in ATN-B1 CPDLC allows for the injection of false emergency or status messages, potentially leading to critical operational confusion and improper responses by flight crews.

Executive summary

A high-severity injection vulnerability in the ATN-B1 CPDLC system poses a significant risk to operational integrity and flight safety by allowing the transmission of unauthorized status messages.

Vulnerability

The vulnerability is an improper input validation flaw (CWE-754) that allows an authenticated attacker to inject deceptive emergency or status messages into the Controller Pilot Data Link Communications system.

Business impact

Successful exploitation could result in the misallocation of aviation resources, significant operational disruption, and potentially dangerous instructions being issued to flight crews. Given the CVSS score of 7.1, this vulnerability represents a high risk to safety-critical infrastructure where incorrect data integrity directly translates to physical operational hazards.

Remediation

Immediate Action: Consult the vendor advisory (ICS-26-219-01) for specific mitigation procedures and contact the manufacturer to determine the availability of security patches.

Proactive Monitoring: Implement strict monitoring of CPDLC message logs for anomalous or unauthorized emergency status commands that deviate from expected communication patterns.

Compensating Controls: Restrict access to the communication network used by CPDLC to authorized personnel only and ensure that all message traffic is subject to secondary verification procedures.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

This vulnerability presents a severe risk to aviation operations. Organizations relying on ATN-B1 CPDLC must prioritize the review of vendor-provided security documentation and implement rigorous access controls to prevent unauthorized message injection until a permanent firmware update is verified and applied.