Impact
The vulnerability resides in the broadcast control frames of the CPDLC protocol stack. An attacker can transmit crafted frames that cause multiple aircraft to be disconnected at once. This denial of service can delay clearances, overload traffic controllers, and create a safety risk. The weakness falls under CWE-770, reflecting a flaw that permits resource exhaustion or availability denial.
Affected Systems
The affected systems are the ATN-B1 CPDLC stack, used in aviation communications. No specific version information is available in the data, so all builds of this product are potentially impacted until a vendor update is released.
Risk and Exploitability
The CVSS score is 6, indicating medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of current exploitation. The attack vector is via remote radio transmission, though the advice from the CNAs indicates that real-world exploitation would require very specific conditions and is considered unlikely outside a lab setting.
OpenCVE Enrichment