CPDLC over ATN-B1 Vulnerabilities

Summary

The ATN-B1 CPDLC system, used in air traffic control communications, suffers from vulnerabilities that allow unauthorized message injection, denial-of-service, and session resets due to its reliance on legacy clear text and unauthenticated radio links. While these do not create an unsafe aircraft condition, they can degrade operational safety by increasing workload and delaying critical instructions.

IFF Assessment

FOE

This article details vulnerabilities in an aviation communication system, which could be exploited to disrupt operations and potentially impact safety.

Severity

7.1 High

Defender Context

This highlights a critical security gap in legacy aviation communication systems, emphasizing the risks associated with unauthenticated protocols. Defenders in the transportation sector should be aware of the potential for message injection and disruption, and monitor for any developing exploitation attempts. The lack of available mitigations underscores the urgency for system updates or alternative secure communication methods.

Read Full Story →