Description
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
Published: 2026-08-07
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the broadcast control frames of the CPDLC protocol stack. An attacker can transmit crafted frames that cause multiple aircraft to be disconnected at once. This denial of service can delay clearances, overload traffic controllers, and create a safety risk. The weakness falls under CWE-770, reflecting a flaw that permits resource exhaustion or availability denial.

Affected Systems

The affected systems are the ATN-B1 CPDLC stack, used in aviation communications. No specific version information is available in the data, so all builds of this product are potentially impacted until a vendor update is released.

Risk and Exploitability

The CVSS score is 6, indicating medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of current exploitation. The attack vector is via remote radio transmission, though the advice from the CNAs indicates that real-world exploitation would require very specific conditions and is considered unlikely outside a lab setting.

Generated by OpenCVE AI on August 7, 2026 at 20:37 UTC.

Remediation

Vendor Workaround

These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.


OpenCVE Recommended Actions

  • Stay alert for vendor releases and apply the latest CPDLC stack update when available.
  • Configure monitoring to detect abnormal disconnect events in the CPDLC system and correlate them with radio traffic logs.
  • Report any suspected manipulation or anomalous activity to CISA and follow internal incident response procedures.
  • If the vendor provides a temporary workaround, apply it as an interim measure while awaiting a definitive patch.

Generated by OpenCVE AI on August 7, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
Title In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultaneously
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-07T19:01:48.118Z

Reserved: 2026-08-04T20:31:35.645Z

Link: CVE-2025-71411

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling