Researchers Demonstrate 60-Second 737 Avionics Attack

Originally published at: Researchers Demonstrate 60-Second 737 Avionics Attack

Proof-of-concept device could alter flight-management data after brief physical access to the aircraft.

“The research team first disclosed the vulnerability to Boeing in 2020”, It is now 2026!

Boeing hasn’t dealt with this in 6 years? Old news?

Anything can be hacked;
Having said that, leaving an easily accessible vulnerability like this is just dumb!
Back when we first got datalink at a major carrier, the company planned to datalink flight plans direct into the FMS;
Which brought to mind the Mt. Erebus disaster; faulty company generated flight plan.
One of the pilot group demonstrated the ability to hack that data link system from a home computer; easily;
The planned uploading was cancelled due to safety implications.
Engineers often think their conceptions are immaculate;
Reality unfortunately too often proves otherwise!

“ Researchers Demonstrate 60-Second 737 Avionics Attack”

And you can tape a wrench to the intake in less than 10.

With my career in information and system security; it is commonly said that with physical access comes ownership. Preventing access to the plane and making it harder to open that hatch would be the first step. The port is probably needed for maintenance and removing or blocking it could impact or remove certain maintenance capabilities. As for authentication? It’s ARINC 429, without changing the whole protocol or adding a completely additional layer of software, authentication is not reasonable. And ARINC in used in GA aircraft also, so this could affect many other planes and not just Boeing (why don’t we hear about Airbus, don’t they use the same bus?)

This topic was automatically closed after 7 days. New replies are no longer allowed.