CVE-2025-71412: In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate
Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71412?
CVE-2025-71412 has a severity rating of high, with a score of 7.1.
How do I fix CVE-2025-71412?
To mitigate CVE-2025-71412, it is recommended to implement stricter validation checks on incoming CPDLC messages.
What impact can CVE-2025-71412 have on operations?
CVE-2025-71412 may result in misallocation of resources, operational confusion, and improper response actions.
Who is affected by CVE-2025-71412?
CVE-2025-71412 affects flight crews, traffic controllers, and ground operations reliant on CPDLC for communication.
What type of attack is associated with CVE-2025-71412?
CVE-2025-71412 involves the injection of false emergency or status messages over CPDLC, which can be executed remotely.