logo

Airbus Navblue Flysmart LPC-NG issues

ID: 053a8e3e-7e19-591a-a341-819aec14d41c

STIX ID: report--053a8e3e-7e19-591a-a341-819aec14d41c

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-10-01

Date Updated: 2026-03-24

Author: PTP Aviation Team

...
...

Researchers found that Airbus Navblue FlySmart LPC-NG (L5.2.3, Windows EFB v17.03) used plaintext performance/airport databases without cryptographic integrity checks, allowing an attacker with local EFB access or access to the update supply chain to alter takeoff and landing performance inputs, potentially leading to runway overruns or CFIT. Airbus initially declined to treat it as a security issue and cited operator mitigations, but after EASA’s involvement the vulnerability was fixed; recommended mitigations include cryptographic signing (PKI) or HMAC for data integrity and consistent EFB hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.