logo

SQL Injection Attack on Airport Security

ID: ea9a61c0-eeb8-51e2-9bca-f91d6c440170

STIX ID: report--ea9a61c0-eeb8-51e2-9bca-f91d6c440170

Feed Name: Schneier on Security

Threat Score
75/100

Date Published: 2024-09-02

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

A researcher discovered SQL injection vulnerabilities in airport/airline systems used for Known Crewmember (KCM) and Cockpit Access Security System (CASS) verification that could let an attacker add unauthorized crew members, enabling bypass of security screening and potential cockpit access; the issue was recognized as serious and disclosure began after discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.