ctipilot.ch

CPDLC over ATN-B1 — malformed or out-of-sequence X.25-layer frames cause repeated resets (CVSS 5.3); no mitigation available

cve · CVE-2025-71413 single-source-national-cert

Coverage timeline
1
first 2026-08-08 → last 2026-08-08
Peak priority
routine
1 routine
Sources cited
1
1 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
4
see Related entities below
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
ATN-B1 CPDLC (Advisory Circular 90-117 Data Link Communications)

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1499Endpoint Denial of Service×1

Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · ATT&CK page ↗

T1565.002Data Manipulation: Transmitted Data Manipulation×1

Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data. By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, and decision making.

Evidence: 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · ATT&CK page ↗

Story timeline

  1. 2026-08-08CISA publishes five protocol-level flaws in CPDLC over ATN-B1, reported by a Swiss armasuisse researcher — no mitigation available, and CISA assesses exploitation unlikely outside a lab
    trending-vulnerabilitiesThe controller-to-cockpit data link has no authentication by design, so the advisory has a remediation status of none-available

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov1 (100%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about CPDLC over ATN-B1 — malformed or out-of-sequence X.25-layer frames cause repeated resets (CVSS 5.3); no mitigation available (1)

2026-08-08 · view entry permalink →

ROUTINECVE-2025-71409 +4NATOA2

CISA publishes five protocol-level flaws in CPDLC over ATN-B1, reported by a Swiss armasuisse researcher — no mitigation available, and CISA assesses exploitation unlikely outside a lab

CISA published ICS advisory ICSA-26-219-01 on 2026-08-07 covering five vulnerabilities in Controller-Pilot Data Link Communications as implemented over the ATN-B1 standard — the data link that carries text clearances and instructions between air traffic controllers and flight crews worldwide, under Advisory Circular 90-117. The advisory's product version is vers:all/*, which is the honest way of saying this is a property of the standard rather than a defect in any implementation: "ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links" (CISA, 2026-08-07).

The five split into two effects. CVE-2025-71409 (CWE-306, CVSS 3.1 7.1) is the absence of authentication for VHF Data Link messages, which lets a rogue ground station inject CPDLC messages producing unexpected or misleading clearances; CVE-2025-71412 (CWE-754, 7.1) covers injection of false emergency or status messages, which CISA describes as potentially leading to misallocation of resources, operational confusion and improper responses by flight crews, controllers and ground operations. The remaining three are availability effects at CVSS 5.3: CVE-2025-71410 (Unnumbered Disconnect and malformed link-control frames terminating sessions and forcing reversion to voice), CVE-2025-71411 (broadcast control frames disconnecting multiple aircraft simultaneously, leading to controller overload) and CVE-2025-71413 (malformed or out-of-sequence frames at the X.25 layer causing repeated resets). Every one is carried out remotely over radio frequency (CISA, 2026-08-07).

Two statements from CISA bound this correctly, and both should travel with any onward summary. On consequence: the vulnerabilities "do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness". On likelihood, from the advisory's machine-readable CSAF record: they "are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting" (CISA, 2026-08-07). The same record gives the remediation category as none-available for all five CVEs. There is no fix to schedule and no configuration to change.

There is a home-region thread: the advisory credits the report to "Martin Strohmeier of Armasuisse", the Swiss federal armaments enterprise (CISA, 2026-08-07).

This is carried for situational awareness in the transport sector rather than as an action item, and it is deliberately shipped without one. Nothing in an enterprise security stack touches an RF data link — the exposure belongs to air navigation service providers, airlines and aviation regulators, at the level of contingency planning for reversion to voice communication and of the multi-year standards work that would add authentication to the protocol. For a defender reading this brief, the useful takeaway is calibration: when reporting on this advisory circulates in less careful form, the two CISA statements above are what keep it in proportion.

ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links.

These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness.

CISA 2026-08-07

These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.

CISA (CSAF record for ICSA-26-219-01)
vulnerability08 Aug 05:25Zsingle-source · national CERTOpen finding ↗
Sources: CISA