PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-11166 Traffic Alert and Collision Avoidance System (TCAS) II CVE debrief

CVE-2024-11166 is a HIGH severity vulnerability (CVSS 3.1: 8.2) affecting Traffic Alert and Collision Avoidance System (TCAS) II aircraft safety systems. Published on January 21, 2024, this vulnerability exists in TCAS II systems using transponders compliant with Minimum Operational Performance Standards (MOPS) earlier than RTCA DO-181F. An attacker with adjacent network access can impersonate a ground station and issue a Comm-A Identity Request, which sets the Sensitivity Level Control (SLC) to its lowest setting and disables the Resolution Advisory (RA) function. This creates a denial-of-service condition that degrades collision avoidance capabilities. CISA notes that while exploitable in laboratory conditions, the vulnerability requires very specific conditions and is unlikely to be exploited outside controlled environments. No known public exploitation has been reported. The vulnerability is not remotely exploitable and carries high attack complexity.

Vendor
Traffic Alert and Collision Avoidance System (TCAS) II
Product
TCAS II
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2024-01-21
Original CVE updated
2024-01-21
Advisory published
2024-01-21
Advisory updated
2024-01-21

Who should care

Aircraft operators, aviation maintenance organizations, fleet managers, pilots, air traffic management authorities, aviation cybersecurity professionals, and regulatory bodies including FAA and international civil aviation organizations should prioritize assessment and remediation of this vulnerability due to its direct impact on flight safety systems.

Technical summary

TCAS II systems with transponders below RTCA DO-181F compliance are vulnerable to ground station impersonation attacks. An attacker on an adjacent network can transmit a Comm-A Identity Request that manipulates the Sensitivity Level Control to minimum settings and disables Resolution Advisory generation. This represents a safety-critical degradation of collision avoidance functionality. The attack requires proximity (adjacent network access) but no privileges or user interaction. The vulnerability affects confidentiality (none), integrity (low), and availability (high) with scope change impact. Remediation requires hardware/software upgrades to ACAS X or DO-181F-compliant transponders.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to ACAS X or upgrade associated transponder to comply with RTCA DO-181F to fully mitigate CVE-2024-11166
  • Follow established internal procedures and report suspected malicious activity to CISA for tracking and correlation
  • Review CISA ICS recommended practices for defense-in-depth strategies applicable to aviation systems
  • Assess transponder MOPS compliance status across affected aircraft fleets
  • Coordinate with FAA and aviation maintenance organizations for remediation planning
  • Monitor for anomalous transponder behavior or unexpected SLC changes during pre-flight and in-flight operations

Evidence notes

Source: CISA CSAF advisory ICSA-25-021-01. CVSS 3.1 vector: AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H. Affected product: TCAS II version 7.1 and earlier with transponders below RTCA DO-181F compliance.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-11166 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-11166

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-11166 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-11166

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-021-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-021-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.