Impact
Malformed or out-of-sequence frames transmitted over the Aviation Very High Frequency Link Control X.25 layer provoke repeated resets of the CPDLC protocol stack, forcing air traffic control personnel to restore services and increasing workload. The resulting disruptions can degrade situational awareness and compromise flight safety. This flaw is identified as a weakness in the handling of session control messages, classified as CWE‑754.
Affected Systems
The affected product is ATN‑B1 CPDLC. No specific version details are provided, so any implementation based on the ATN‑B1 stack may be impacted.
Risk and Exploitability
The CVSS score of 6 indicates a medium severity, while the EPSS score is not available, leaving exploitation probability uncertain. The CVE is not listed in CISA KEV, suggesting no publicly documented exploits at present. The attack vector is remote, occurring over the radio frequency link used by CPDLC, and requires an adversary capable of injecting malformed frames into that line. The vendor’s advisory stresses that the conditions for exploitation are highly specific, making real-world attacks outside of controlled lab environments unlikely.
OpenCVE Enrichment