CVE-2025-71411

Summary

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

Affected Software

VendorProductVersion RangeStatus
ATN-B1CPDLCAll versionsaffected

Weaknesses

  • CWE-770: CWE-770

Workarounds

These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

References