Sceawere
Vulnerability Detail
CVE-2025-71411UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Aircraft Disconnection via Broadcast Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 18h ago
- Vendor
- ATN-B1
- Product
- CPDLC
- Attack Type
- CWE-770
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-07T19:17:34.047Z",
"pubdate": "2026-08-07T19:17:34.047Z",
"executiveSummary": "The identified vulnerability involves the processing of broadcast control frames within aviation communication systems, which can be maliciously exploited to induce simultaneous disconnections across multiple aircraft. This security flaw presents significant operational risks to critical infrastructure, specifically impacting air traffic management and flight operations.\nThe primary impact of successful exploitation includes delayed flight clearances, acute air traffic controller overload, and a degradation of situational awareness in controlled airspace. The vulnerability resides in wireless communication components utilized by aircraft and ground stations, making the attack surface accessible via radio frequency (RF) transmissions.\nThreat actors possessing remote capabilities and appropriate RF transmission equipment can execute this attack without requiring prior authentication, physical access, or elevated privileges. The exploitation vector leverages the inherent trust in unauthenticated or inadequately secured broadcast control frames, allowing malicious signals to propagate across targeted communication channels.\nGiven the remote exploitability and the potential for widespread disruption in safety-critical environments, the risk implications are severe. Mitigation requires addressing the handling of broadcast frames, implementing cryptographic authentication mechanisms for RF communications, and deploying robust anomaly detection systems to identify unauthorized control signals within the aviation network.",
"technicalDetails": "The root cause of this vulnerability lies in the architectural design of legacy or insufficiently secured aviation communication protocols that process broadcast control frames without adequate cryptographic validation or integrity verification. In such systems, broadcast frames are typically trusted by design to ensure rapid dissemination of operational commands and network management messages across the shared wireless medium.\nThe vulnerable component comprises the radio frequency receiver and the underlying link-layer protocol stack responsible for parsing and executing control directives on affected aircraft and ground infrastructure. Because these frames lack mandatory authentication or message integrity checks, any entity within transmission range can generate and broadcast forged control primitives.\nThe attack flow proceeds as follows: First, the attacker positions an RF transmitter within operational proximity of the targeted aviation communication frequencies. Second, the attacker crafts malicious broadcast control frames designed to command connected stations to terminate their active sessions or disconnect from the network. Third, the attacker transmits these fabricated frames over the air interface. Fourth, upon receiving the malicious broadcast frames, the vulnerable communication components on multiple aircraft process the instructions as legitimate commands. Finally, the affected systems synchronously tear down their active connections, leading to simultaneous disconnections across the fleet.\nExploitation occurs entirely remotely over radio frequency channels, requiring no prior authentication, pre-existing privileges, or interaction from flight crews or air traffic controllers. The payload behavior involves issuing standardized or custom disconnect primitives that exploit the state-machine logic of the targeted link-layer protocol, forcing a transition to an unlinked or idle state.\nThe post-exploitation impact includes the immediate loss of data links between the affected aircraft and ground control, resulting in delayed clearances, communication blackouts, and substantial cognitive overload for air traffic controllers who must manage multiple uncoordinated or abruptly disconnected flights simultaneously. The lack of cryptographic hardening in the affected protocol specifications enables this denial-of-service condition to be scaled across a broad geographic area depending on the transmission power utilized by the threat actor."
}