Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 08 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Atn-b1
Atn-b1 cpdlc |
|
| Vendors & Products |
Atn-b1
Atn-b1 cpdlc |
Fri, 07 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency. | |
| Title | No Authentication for Very High Frequency Data Link messages used in CPDLC | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-10T18:24:59.021Z
Reserved: 2026-08-04T20:31:35.645Z
Link: CVE-2025-71409
Updated: 2026-08-10T18:19:32.833Z
Status : Received
Published: 2026-08-07T19:17:33.720
Modified: 2026-08-10T19:17:27.210
Link: CVE-2025-71409
No data.
OpenCVE Enrichment
Updated: 2026-08-08T20:40:36Z