CVE-2025-71413
Received Received - Intake

Aviation VHF Link Control X.25 Frame Reset Vulnerability

Vulnerability report for CVE-2025-71413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: ICS-CERT

Description

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remotely over radio frequency.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers. It causes repeated resets which may increase workload and reduce situational awareness for operators. The attack can be executed remotely over radio frequency.

Detection Guidance

Detection may involve monitoring for repeated resets or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers. Specific commands depend on the system but could include network traffic analyzers like Wireshark to inspect X.25 protocol frames for anomalies.

Impact Analysis

The vulnerability may lead to operational disruptions in aviation systems due to repeated resets. This could cause increased workload for personnel and reduced situational awareness, potentially affecting flight safety and efficiency.

Compliance Impact

The vulnerability involves malformed frames causing repeated resets in aviation communication systems, which may reduce situational awareness. This could indirectly impact compliance with standards like GDPR or HIPAA by compromising data integrity or availability in systems that rely on these communication protocols.

Mitigation Strategies

Implement strict input validation for X.25 frames, update firmware or software to handle malformed frames gracefully, and monitor network traffic for unusual reset patterns. Isolate affected systems if possible to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-71413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart