PatchSiren cyber security CVE debrief
CVE-2024-11166 Traffic Alert and Collision Avoidance System (TCAS) II CVE debrief
CVE-2024-11166 is a HIGH severity vulnerability (CVSS 3.1: 8.2) affecting Traffic Alert and Collision Avoidance System (TCAS) II aircraft safety systems. Published on January 21, 2024, this vulnerability exists in TCAS II systems using transponders compliant with Minimum Operational Performance Standards (MOPS) earlier than RTCA DO-181F. An attacker with adjacent network access can impersonate a ground station and issue a Comm-A Identity Request, which sets the Sensitivity Level Control (SLC) to its lowest setting and disables the Resolution Advisory (RA) function. This creates a denial-of-service condition that degrades collision avoidance capabilities. CISA notes that while exploitable in laboratory conditions, the vulnerability requires very specific conditions and is unlikely to be exploited outside controlled environments. No known public exploitation has been reported. The vulnerability is not remotely exploitable and carries high attack complexity.
- Vendor
- Traffic Alert and Collision Avoidance System (TCAS) II
- Product
- TCAS II
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-01-21
- Original CVE updated
- 2024-01-21
- Advisory published
- 2024-01-21
- Advisory updated
- 2024-01-21
Who should care
Aircraft operators, aviation maintenance organizations, fleet managers, pilots, air traffic management authorities, aviation cybersecurity professionals, and regulatory bodies including FAA and international civil aviation organizations should prioritize assessment and remediation of this vulnerability due to its direct impact on flight safety systems.
Technical summary
TCAS II systems with transponders below RTCA DO-181F compliance are vulnerable to ground station impersonation attacks. An attacker on an adjacent network can transmit a Comm-A Identity Request that manipulates the Sensitivity Level Control to minimum settings and disables Resolution Advisory generation. This represents a safety-critical degradation of collision avoidance functionality. The attack requires proximity (adjacent network access) but no privileges or user interaction. The vulnerability affects confidentiality (none), integrity (low), and availability (high) with scope change impact. Remediation requires hardware/software upgrades to ACAS X or DO-181F-compliant transponders.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade to ACAS X or upgrade associated transponder to comply with RTCA DO-181F to fully mitigate CVE-2024-11166
- Follow established internal procedures and report suspected malicious activity to CISA for tracking and correlation
- Review CISA ICS recommended practices for defense-in-depth strategies applicable to aviation systems
- Assess transponder MOPS compliance status across affected aircraft fleets
- Coordinate with FAA and aviation maintenance organizations for remediation planning
- Monitor for anomalous transponder behavior or unexpected SLC changes during pre-flight and in-flight operations
Evidence notes
Source: CISA CSAF advisory ICSA-25-021-01. CVSS 3.1 vector: AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H. Affected product: TCAS II version 7.1 and earlier with transponders below RTCA DO-181F compliance.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-11166 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-11166
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-11166 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-11166
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-021-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-021-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.