Remote Message Injection Vulnerability in Air Traffic Control Systems by CISA
CVE-2025-71412
7.1HIGH
What is CVE-2025-71412?
This vulnerability allows for the remote injection of false emergency or status messages into Controller-Pilot Data Link Communications (CPDLC) systems. Such an attack can create operational confusion, leading to misallocation of resources and inappropriate response actions from flight crews, air traffic controllers, and ground operations. With the potential for exploitation over radio frequencies, this vulnerability poses significant risks to air traffic safety and management.
Affected Version(s)
CPDLC All versions
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Martin Strohmeier of Armasuisse reported this vulnerability to CISA.
