CPDLC over ATN-B1 Vulnerabilities — ICSA-26-219-01
CISA ICS · CISA · ICSA-26-219-01
ID
ICSA-26-219-01
ICSA-26-219-01
Date
Source
CISA ICS
CISA ICS
Vendor
CISA
CISA
Threat
medium
medium
Summary
View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions,…
Timeline
- Published by source
- 2026-08-07
Risk context
- Reported severity or threat level: medium.
- Review exposure for the affected product or family: ICS Advisory.
Product
ICS Advisory
What to do
General, cautious steps (verify details in the official source):
- Review exposure and plan remediation based on risk and environment.
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- ICSA-26-219-01
- Source
- CISA ICS
- Vendor
- CISA
- Published by source
- 2026-08-07
- Last source activity
- 2026-08-07
- Additional identifiers
- CVE-2025-71409
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.