CVE-2025-71410: Malicious Link Control Frames Can Cause Loss of CPDLC Functions
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the risk of remote RF attacks using unnumbered disconnect (U DISC) and malformed Aviation VHF Link Control frames by restricting/monitoring CPDLC-related RF communications and disconnect-related behavior as appropriate to your ATC/CPDLC system environment, since the attack can terminate sessions and force reversion to voice communication.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71410?
The severity of CVE-2025-71410 is rated as medium with a score of 5.3.
How does CVE-2025-71410 affect CPDLC functions?
CVE-2025-71410 can cause a loss of CPDLC functions due to unnumbered disconnects and malformed link control frames.
What type of attack is associated with CVE-2025-71410?
CVE-2025-71410 involves remote attacks using malicious link control frames over radio frequencies.
What are the potential consequences of CVE-2025-71410?
The potential consequences of CVE-2025-71410 include increased controller workload and a reversion to voice communication.
How can organizations mitigate the risks of CVE-2025-71410?
Organizations should implement security measures to monitor and control radio frequency communications to mitigate the risks of CVE-2025-71410.