CPDLC over ATN-B1 Vulnerabilities
ATN-B1 CPDLC (Controller-Pilot Data Link Communications) relies on legacy clear-text, unauthenticated VHF radio frequency links. These characteristics allow unauthorized message injection, denial-of-service attacks, and forced session resets. While not creating an unsafe aircraft condition per se, these vulnerabilities can degrade operational safety margins by increasing pilot workload, delaying critical instructions, and reducing situational awareness. The vulnerabilities require very specific conditions and high attack complexity to exploit, and no known public exploitation has been reported.
- Access to VHF radio frequency band in the aircraft's operational area
- Knowledge of CPDLC protocol message format and timing
- Ability to transmit on the same frequency as active CPDLC sessions
- High attack complexity; specific environmental and timing conditions required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c9194ef0-74db-44aa-afa7-878b5d358ab2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.