CISA publishes five protocol-level flaws in CPDLC over ATN-B1, reported by a Swiss armasuisse researcher — no mitigation available, and CISA assesses exploitation unlikely outside a lab
CISA published ICS advisory ICSA-26-219-01 on 2026-08-07 covering five vulnerabilities in Controller-Pilot Data Link Communications as implemented over the ATN-B1 standard — the data link that carries text clearances and instructions between air traffic controllers and flight crews worldwide, under Advisory Circular 90-117. The advisory's product version is vers:all/*, which is the honest way of saying this is a property of the standard rather than a defect in any implementation: "ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links" (CISA, 2026-08-07).
The five split into two effects. CVE-2025-71409 (CWE-306, CVSS 3.1 7.1) is the absence of authentication for VHF Data Link messages, which lets a rogue ground station inject CPDLC messages producing unexpected or misleading clearances; CVE-2025-71412 (CWE-754, 7.1) covers injection of false emergency or status messages, which CISA describes as potentially leading to misallocation of resources, operational confusion and improper responses by flight crews, controllers and ground operations. The remaining three are availability effects at CVSS 5.3: CVE-2025-71410 (Unnumbered Disconnect and malformed link-control frames terminating sessions and forcing reversion to voice), CVE-2025-71411 (broadcast control frames disconnecting multiple aircraft simultaneously, leading to controller overload) and CVE-2025-71413 (malformed or out-of-sequence frames at the X.25 layer causing repeated resets). Every one is carried out remotely over radio frequency (CISA, 2026-08-07).
Two statements from CISA bound this correctly, and both should travel with any onward summary. On consequence: the vulnerabilities "do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness". On likelihood, from the advisory's machine-readable CSAF record: they "are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting" (CISA, 2026-08-07). The same record gives the remediation category as none-available for all five CVEs. There is no fix to schedule and no configuration to change.
There is a home-region thread: the advisory credits the report to "Martin Strohmeier of Armasuisse", the Swiss federal armaments enterprise (CISA, 2026-08-07).
This is carried for situational awareness in the transport sector rather than as an action item, and it is deliberately shipped without one. Nothing in an enterprise security stack touches an RF data link — the exposure belongs to air navigation service providers, airlines and aviation regulators, at the level of contingency planning for reversion to voice communication and of the multi-year standards work that would add authentication to the protocol. For a defender reading this brief, the useful takeaway is calibration: when reporting on this advisory circulates in less careful form, the two CISA statements above are what keep it in proportion.
ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links.
These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness.
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.
ATT&CK mapping
2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Impact TA0040
T1499Endpoint Denial of Service
Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
T1565.002Data Manipulation: Transmitted Data Manipulation
Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data. By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, and decision making.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.