Aviation Alert: Legacy Air Traffic Communication System Vulnerable to Message Injection Attacks
CISA has issued an advisory covering five vulnerabilities affecting Controller-Pilot Data Link Communications (CPDLC) over the ATN-B1 standard, a system used for text-based communication between air traffic controllers and pilots. The core issue is that ATN-B1 CPDLC relies on legacy, unencrypted, unauthenticated radio frequency links, meaning messages are sent as plain text without verification of the sender.
Research has shown these weaknesses could allow attackers to inject unauthorized messages into the communication channel, trigger denial-of-service conditions, or force session resets. Importantly, CISA notes these flaws do not create an unsafe aircraft condition on their own, but they can degrade safety margins by increasing controller and pilot workload, delaying critical instructions, and reducing situational awareness during flight operations.
While this advisory is specific to aviation infrastructure rather than typical small business IT systems, it's a useful reminder of a broader lesson: systems built on old, unauthenticated communication protocols remain vulnerable no matter how critical the industry. Businesses relying on legacy systems, whether in operational technology, point-of-sale, or internal communications, should take note that unauthenticated, unencrypted channels are a persistent and serious risk across sectors.