Description
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.
Published: 2026-08-07
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate CPDLC sessions, causing a loss of system functions and forcing controllers to revert to voice communication. The flaw is a resource exhaustion weakness that can be exploited remotely over radio frequency, leading to a denial of CPDLC service and increased controller workload.

Affected Systems

The vulnerability affects ATN‑B1 CPDLC protocol stack implementations. No specific version details are disclosed, so any ATN‑B1 CPDLC stack is potentially impacted.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, implying limited observed exploitation. It requires highly specific laboratory conditions, making field exploitation unlikely, but the remote radio attack vector means monitoring and reporting are prudent until a vendor patch becomes available.

Generated by OpenCVE AI on August 7, 2026 at 20:37 UTC.

Remediation

Vendor Workaround

These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.


OpenCVE Recommended Actions

  • Implement continuous monitoring for anomalous CPDLC session terminations caused by malformed LC frames and investigate any suspected activity promptly.
  • Follow internal incident response procedures and report suspected malicious activity to CISA for tracking and correlation.
  • Apply the vendor‑released patch or upgrade the CPDLC protocol stack as soon as an official fix is available.

Generated by OpenCVE AI on August 7, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Atn-b1
Atn-b1 cpdlc
Vendors & Products Atn-b1
Atn-b1 cpdlc

Fri, 07 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.
Title Malicious Link Control Frames Can Cause Loss of CPDLC Functions
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-10T21:13:04.861Z

Reserved: 2026-08-04T20:31:35.645Z

Link: CVE-2025-71410

cve-icon Vulnrichment

Updated: 2026-08-10T18:42:19.071Z

cve-icon NVD

Status : Received

Published: 2026-08-07T19:17:33.893

Modified: 2026-08-10T22:17:08.767

Link: CVE-2025-71410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:40:38Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling