IM
IronMonkey Threat Research

CVE-2025-71412 HIGH

Published: 2026-08-07 | Last Modified: 2026-08-07 | Status: Received

Description

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.

CVSS Metrics

Base Score: 7.1 (HIGH)

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactLOW

Source: [email protected]

Type: Secondary

Exploitability Score: 1.8

Impact Score: 4.7

Base Score: 7.1 (HIGH)

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityHIGH
Attack RequirementsNONE
Privileges RequiredLOW
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityHIGH
Vulnerability AvailabilityLOW
Subsequent ConfidentialityNONE
Subsequent IntegrityHIGH
Subsequent AvailabilityLOW

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Primary
en CWE-754
Notification
Message here