started · updated
Boeing 737 vulnerability exposed by cybersecurity researchers
Researchers from the University of California San Diego and Oberlin College have demonstrated that a Boeing 737 can be compromised in less than 60 seconds using a small, custom hardware device. The device, which is roughly the size of a coin and costs approximately $100, targets the communication between the flight management computer and the cockpit display computer.
To execute the attack, an individual only needs brief physical access to an unused maintenance port located in the aircraft's Electronics and Equipment (E&E) bay. This compartment, situated under the nose section of the fuselage, is accessible from the ground and is not locked. The researchers noted that the breach can occur whether the plane is parked at a gate or inside a hangar.
The exploit allows an attacker to potentially alter flight plans or navigation data without the changes appearing on the pilots' instruments. The study aims to alert the aviation industry to these physical security vulnerabilities so that mitigations can be implemented before such methods are exploited by malicious actors.
Entities
Boeing · Oberlin College · University of California San Diego