Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
After consulting with the Federal Aviation Administration (FAA) and the researchers regarding these vulnerabilities, it has been concluded that CVE-2024-11166 can be fully mitigated by upgrading to ACAS X or by upgrading the associated transponder to comply with RTCA DO-181F. Currently, there is no mitigation available for CWE-2024-9310. These vulnerabilities in the TCAS II standard are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely. These vulnerabilities have a high attack complexity.
Wed, 12 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 22 Jan 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a ground station and issue a Comm-A Identity Request. This action can set the Sensitivity Level Control (SLC) to the lowest setting and disable the Resolution Advisory (RA), leading to a denial-of-service condition. | |
Title | Traffic Alert and Collision Avoidance System (TCAS) II has an External Control of System or Configuration Setting vulnerability | |
Weaknesses | CWE-15 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-12T17:08:00.961Z
Reserved: 2024-11-12T21:01:21.756Z
Link: CVE-2024-11166

Updated: 2025-02-12T17:07:46.891Z

Status : Received
Published: 2025-01-22T19:15:09.890
Modified: 2025-01-22T19:15:09.890
Link: CVE-2024-11166

No data.

No data.