Aircraft Collision: ICS Flaw Risks Mid-Air Crashes
ID: cc454c28-0ed0-5186-8cde-132e608fec49
STIX ID: report--cc454c28-0ed0-5186-8cde-132e608fec49
Feed Name: Cyble Blog
This report summarizes two vulnerabilities in the TCAS II aircraft collision-avoidance system (CVE-2024-9310 and CVE-2024-11166): one allows spoofed RF inputs to fabricate targets and currently has no mitigation, and the other can be exploited via impersonating ground stations to lower sensitivity and disable Resolution Advisories but can be mitigated by upgrading to ACAS X or RTCA DO-181F-compliant transponders; both were demonstrated in lab conditions and Cyble/CISA urge ICS security controls such as patch management, zero-trust, network segmentation, and incident response preparedness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
