GAO Warns of Cybersecurity Vulnerabilities in FAA Air Traffic Control Systems
The U.S. Government Accountability Office (GAO) has issued a warning regarding significant cybersecurity vulnerabilities within the Federal Aviation Administration's (FAA) air traffic control systems. The report indicates that malicious actors could exploit weaknesses in authentication, encryption, and protocol design of systems like the Aircraft Communications Addressing and Reporting System (ACARS) and Controller-Pilot Data Link Communications (CPDLC). These vulnerabilities could allow for the transmission of fraudulent messages, including fake clearance cancellations, potentially leading to flight delays or safety issues. The GAO found that the FAA lacks comprehensive real-time threat monitoring and has not completed necessary risk assessments and security documentation for several spectrum-dependent systems. The FAA concurred with all nine recommendations made by the GAO, which include strengthening authentication and data protection, conducting spectrum risk assessments, and improving interagency coll...