Crucial Airline Flight Planning App Open to Interception Risks
ID: c5d5ebd1-258c-58f2-9f95-709547820a75
STIX ID: report--c5d5ebd1-258c-58f2-9f95-709547820a75
Feed Name: Dark Reading
Pen Test Partners disclosed that Navblue's Flysmart+ Manager iOS app had App Transport Security disabled and lacked certificate validation, enabling a man-in-the-middle attack during app updates that could allow tampering with flight performance and planning data; although exploitation requires proximity (e.g., pilot layover Wi‑Fi) and timing during updates, the flaw could lead to incorrect engine power or braking calculations and pose safety risks if abused, and Navblue has since remediated the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
