CVE-2024-11166 describes a denial-of-service vulnerability affecting TCAS II systems utilizing transponders compliant with MOPS earlier than RTCA DO-181F. An attacker can impersonate a ground station to issue a Comm-A Identity Request, which sets the Sensitivity Level Control to its lowest setting and disables Resolution Advisories. This vulnerability carries a CVSSv4 score of 7.1 (HIGH), indicating a low-complexity attack requiring adjacent network access, with a high impact on availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Traffic Alert And Collision Avoidance System (TCAS) II | Collision Avoidance Systems | 7.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.