Boeing 737 Flight Systems Vulnerable to Physical Access Hacks
A team of researchers from the University of California San Diego has demonstrated how an attacker could gain control over Boeing 737 flight systems using a custom hardware device connected to an aircraft maintenance interface.
The attack, which relies on reaching an electronics bay beneath the aircraft's nose, can be completed in under 60 seconds. The team estimates that connecting the device would take less than a minute, and researchers argue that physical access deserves more attention in aviation cybersecurity.
The vulnerable communications rely on ARINC 429 data buses, which were not designed with contemporary cybersecurity protections. Researchers built their device to impersonate a legitimate participant on the communication link, demonstrating how it could interfere with legitimate data and introduce its own messages.