Boeing 737 Vulnerability Allows Attackers to Manipulate Flight Computer
Researchers at the University of California San Diego and Oberlin College have discovered a vulnerability in Boeing's 737 aircraft, allowing an attacker to manipulate the flight computer with ease. In their study, they designed a small hardware device that can be inserted into the plane's maintenance port in under 60 seconds, giving them access to the ARINC 429 communication system.
The team found that by exploiting this weakness, the implant could override legitimate data signals and hide the tampering from pilots. They demonstrated three specific ways it could interfere with the flight computer: changing the flight route, altering weight and balance data, and manipulating the assumed outside air temperature.
Boeing was informed of the vulnerability in April 2020 and allowed the researchers to test their prototype in their own 737 testing facility. While the company stated that existing layers of protection 'significantly limit' the real-world feasibility of such an attack, the researchers emphasized that they do not believe attacks like this are imminent.