Impact
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate CPDLC sessions, causing a loss of system functions and forcing controllers to revert to voice communication. The flaw is a resource exhaustion weakness that can be exploited remotely over radio frequency, leading to a denial of CPDLC service and increased controller workload.
Affected Systems
The vulnerability affects ATN‑B1 CPDLC protocol stack implementations. No specific version details are disclosed, so any ATN‑B1 CPDLC stack is potentially impacted.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, implying limited observed exploitation. It requires highly specific laboratory conditions, making field exploitation unlikely, but the remote radio attack vector means monitoring and reporting are prudent until a vendor patch becomes available.
OpenCVE Enrichment