Crucial Airline Flight Planning App Open to Interception Risks

A mobile app that many airline pilots use for crucial flight planning purposes was open to attacks that could have interfered with safe takeoff and landing procedures due to a disabled security feature it contained.
NAVBLUE, an Airbus-owned IT services company that developed the app, fixed the issue last year after researchers at UK-based Pen Test Partners informed the company about the issue.
Electronic Flight Bag Apps The vulnerability was present in Flysmart+ Manager, an app that is part of a broader suite of Flysmart+ apps for so-called Electronic Flight Bag platforms.
An EFB device - usually an iPad or other tablet computer - basically hosts apps that flight crews use for flight planning calculations and for accessing a variety of digital documents such as operating manuals, navigational charts, and aircraft checklists.
Some EFBs are directly integrated into the avionics systems of modern aircraft and provide an array of other more complex features, such as providing real-time weather information and tracking the aircraft's position on navigational systems.
Flysmart+ specifically is a suite of iOS apps that assists with aircraft performance, weight, and balance-related calculations according to NAVBLUE. It can be fully integrated with Airbus' standard operating procedures, can be used during all phases of a flight, and provides pilots with access to a range of avionics parameters.
Flysmart+ Manager, the app in which Pen Test Partners found the security issue, is an app that enables synchronization of data across the Flysmart+ suite.
Disabled Security Setting Researchers from Pen Test Partners found that an App Transport Security feature in Flysmart+ Manager that would have forced the app to use HTTPS had not been enabled.
The app did not have any form of certificate validation either, leaving it exposed to interception on open and untrusted networks.
Ken Munro, a partner at the pen testing firm, says the biggest concern had to do with the potential for attacks on the app that could cause so called runway excursions - or veer-offs and overruns - and potential tail strikes on takeoff.
The ATS issue in Flysmart+ Manager is just one of several vulnerabilities that PTP has uncovered in EFBs in recent years.
In May 2023 the firm reported an integrity check bypass flaw in a Lufthansa EFB app called Lido eRouteManual that gave attackers a way to modify flight planning data that pilots using the app received.
In July 2022, researchers at PTP showed how they could modify manuals on an EFB pertaining to the effectiveness of de-icing procedures on aircraft wings.
Hard to Exploit From a practical standpoint the disabled ATS setting issue that PTP identified in the Airbus EFB was not especially easy to exploit.
To pull it off, an attacker would have first needed to be within Wi-Fi range of an EFB with the vulnerable app.
More significantly, the attack would have been possible only during an app update - meaning the threat actor would need to know when the update was happening so they could insert their malicious code during the process.
According to PTP, those conditions can occur during pilot layovers.
Pilots usually bring their EFBs with them during layovers because the devices contain their electronic roster as well, Munro says.
If an attacker was within Wi-Fi range of the device at a hotel they could potentially initiate an attack.
While an attack can only happen during an app update, such updates need to happen on a regular basis, he adds.


This Cyber News was published on www.darkreading.com. Publication date: Tue, 06 Feb 2024 20:10:15 +0000


Cyber News related to Crucial Airline Flight Planning App Open to Interception Risks

Crucial Airline Flight Planning App Open to Interception Risks - A mobile app that many airline pilots use for crucial flight planning purposes was open to attacks that could have interfered with safe takeoff and landing procedures due to a disabled security feature it contained. NAVBLUE, an Airbus-owned IT ...
1 year ago Darkreading.com
Hawaiian Airlines discloses cyberattack, flights not affected - Hawaiian Airlines also hired external cybersecurity experts to asses the attack's impact and help restore affected systems. The airline stated in a statement issued on Thursday morning that the incident didn't affect flight safety and has already ...
6 months ago Bleepingcomputer.com
Business Data Backup and Recovery Planning - Data backup and recovery planning is essential in today's interconnected and data-driven business landscape. By understanding the significance of data backup and recovery planning, businesses can effectively protect their critical information and ...
1 year ago Securityzap.com
Data in apps used for aircraft safety remotely tampered with The Register - Criminals could remotely tamper with the data that apps used by airplane pilots rely on to inform safe takeoff and landing procedures, according to fresh research. In a scenario that elicits strong memories of that nail-biting flight scene from Die ...
1 year ago Go.theregister.com
CVE-2025-29154 - HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicitacao_treinamento/, .galera.app/rh/metas/perspectiva_estrategica/edicao/, ...
8 months ago
Fake app impersonating LastPass spotted in Apple's App Store The Register - LastPass says a rogue application impersonating its popular password manager made it past Apple's gatekeepers and was listed in the iOS App Store for unsuspecting folks to download and install. A screenshot of the fake LastPass app in the Apple App ...
1 year ago Go.theregister.com
From Implicit to Authorization Code With PKCE, BFF - Lack of Refresh Token Support occurs when there are no refresh tokens, and frequent requests for new tokens are necessary, increasing the chances of token leakage and misuse. The Implicit Flow had several security vulnerabilities, such as token ...
1 year ago Feeds.dzone.com
How to Keep Cyberattacks From Taking Off - COMMENTARY. Over the last three years, the global aviation industry has been left reeling by a post-pandemic sucker punch that hit the sector with over $185 billion in losses. Once a bastion of American prosperity, airlines were forced into survival ...
2 years ago Darkreading.com
Qantas airline reduces bonuses for executives after data breach - Qantas Airways has taken a significant step in response to a recent data breach by reducing bonuses for its executives. This move underscores the airline's commitment to accountability and cybersecurity resilience. The breach exposed sensitive ...
4 months ago Therecord.media
Fake LastPass password manager spotted on Apple's App Store - LastPass is warning that a fake copy of its app is being distributed on the Apple App Store, likely used as a phishing app to steal users' credentials. The fake app uses a similar name to the genuine app, a similar icon, and a red-themed interface ...
1 year ago Bleepingcomputer.com
Regional airline envoy Oracle hacked, data leaked - The article reports a significant cybersecurity incident involving the hacking of Oracle, a regional airline envoy, leading to a data breach. This breach exposed sensitive information, highlighting the vulnerabilities in airline and aviation sector ...
2 months ago Therecord.media
Collins Aerospace working on restoring software for airlines hit by cyber attack - Collins Aerospace, a major player in the aerospace and defense sector, is actively engaged in restoring software systems for airlines affected by a recent cyber attack. The incident disrupted critical airline operations, highlighting the increasing ...
3 months ago Reuters.com
Australian charged for 'Evil Twin' WiFi attack on plane - An Australian man was charged by Australia's Federal Police for allegedly conducting an 'evil twin' WiFi attack on various domestic flights and airports in Perth, Melbourne, and Adelaide to steal other people's email or social media credentials. The ...
1 year ago Bleepingcomputer.com
Ushering in the Next Phase of Mobile App Adoption: Bolstering Growth with Unyielding Security - In recent years, mobile apps have surged in popularity providing consumers with instant access to a variety of life essentials such as finances, education, and healthcare to life's pleasures such as shopping, sports, and gaming. With the popularity ...
2 years ago Cyberdefensemagazine.com
Business Continuity Planning - CISO’s Critical Role - In the evolving landscape of cyber threats, the Chief Information Security Officer (CISO) plays a critical role in strengthening organizational resilience and advancing Business Continuity Planning to ensure sustained business operations. When CISOs ...
8 months ago Cybersecuritynews.com
Qantas Airlines Hit by Cyberattack, Customer Data Compromised - Australia’s flagship carrier, Qantas Airways, has disclosed a significant cybersecurity breach affecting up to 6 million customers, with cybercriminals gaining unauthorized access to a third-party customer service platform used by the ...
6 months ago Cybersecuritynews.com
The Art of Securing Cloud-Native Mobile Applications - We will explore the dynamic intersection of cloud-native architecture and mobile application security, delving into the strategies and best practices essential for safeguarding sensitive data, ensuring user privacy, and fortifying against emerging ...
2 years ago Feeds.dzone.com
Secure Financial Apps: Proactive Measures - People are using multiple apps to transfer, invest, and save money as per their requirements. These are some of the scenarios within a financial app where cybersecurity can play a key role in averting fraudulent transactions. Of late, a lot of ...
2 years ago Feeds.dzone.com
CVE-2020-26212 - GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.3, any authenticated user ...
5 years ago
Data In-Flight: Applying Zero Trust to Airline Travel and Content Security - No matter which airport you travel through or how many times you travel through it, one element remains the same - the security check(s). Whether you're asked to take off your shoes, put your laptop in a separate bin, or leave it all together and ...
2 years ago Securityboulevard.com
Web-to-App Funnels: Pros And Cons - These funnels are designed to guide users from a web touchpoint (such as an ad or landing page) into a mobile application, where deeper engagement and higher conversions often occur. FunnelFox supports this journey by integrating web traffic sources, ...
5 months ago Cybersecuritynews.com
Role of Parents in Teaching Online Safety - In today's digital landscape, where children are increasingly exposed to the vast world of the internet, the role of parents in teaching online safety has become paramount. Parents should have regular conversations with their kids about the ...
2 years ago Securityzap.com
Lost in Translation: Mitigating Cybersecurity Risks in Multilingual Environments - With increased connectivity and linguistic diversity comes a new set of cybersecurity risks. This article will delve into the unique cybersecurity challenges in multilingual environments, focusing on solutions and best practices to mitigate such ...
2 years ago Cyberdefensemagazine.com
Russian Airline Suffers Cyberattack Disrupting Operations - A major Russian airline recently fell victim to a significant cyberattack that disrupted its operations and compromised sensitive data. The attack highlights the growing threat landscape targeting the aviation sector, where cybercriminals aim to ...
3 months ago Cybersecuritynews.com
What Do Apple's EU App Store Changes Mean for App Developers? - In order to comply with the European Union's Digital Markets Act, Apple announced on Jan. 25 changes to its payment system for app sellers in the EU, and that it was letting go of the hold its App Store has over iOS app distribution in the EU. As ...
1 year ago Techrepublic.com