Unauthenticated CPDLC over ATN‑B1 Links Enable Message Injection and DoS (CVE‑2025‑71409‑71413)
What It Is — The CISA advisory (ICS‑A‑26‑219‑01) documents five CVEs (CVE‑2025‑71409 – CVE‑2025‑71413) affecting the Controller‑Pilot Data Link Communications (CPDLC) implementation over ATN‑B1. The legacy radio‑frequency link transmits clear‑text, unauthenticated messages, allowing a rogue ground station to inject, reset, or flood traffic.
Exploitability — The flaws are remotely exploitable over the VHF data link; no public exploit code is required, only a radio transmitter capable of mimicking a legitimate ground station. CVSS v3 base score 7.1 (High).
Affected Products — All versions of ATN‑B1 CPDLC (global deployments across civil aviation).
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The missing authentication maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); evidence of these controls must be continuously collected.
- Continuous Monitoring – Real‑time telemetry of link‑level traffic provides audit‑ready proof that only authorized stations are communicating.
- Defensible Audit Trail – Documenting mitigation (e.g., cryptographic authentication, traffic throttling) satisfies both regulator‑driven safety mandates and SOC 2’s “risk mitigation” criteria, which enterprise buyers now demand.
Recommended Actions
- Map the gap to SOC 2 control CC6.1 and update your control inventory.
- Deploy interim mitigations (frequency filtering, radio‑frequency monitoring) while a vendor‑issued firmware update is evaluated.
- Capture and retain link‑level logs as continuous evidence for audit readiness.
- Incorporate the authentication requirement into your change‑management workflow and test for regression.