Executive brief
A vulnerability in the Airbus TETRA Connectivity Server, a system used for critical radio communications, could allow an attacker to gain full control over the server. By exploiting incorrect folder permissions, an attacker can trick a user into placing a malicious file that grants the attacker administrative (SYSTEM) privileges. This could lead to a complete service outage or unauthorized access to sensitive communication data.
Technical details
The vulnerability is classified as CWE-276 (Incorrect Default Permissions) within the Airbus PSS TETRA Connectivity Server version 7.0 running on Windows Server OS. The application installs directories with insecure access control lists (ACLs), allowing low-privileged users to write files into sensitive locations. An attacker can achieve arbitrary code execution with SYSTEM privileges by utilizing a social engineering component (user interaction) to place a malicious file in the affected directory. A fix has been developed and distributed to impacted customers.
Affected products
- Airbus TETRA Connectivity Server 7.0
Timeline
- 2026-04-03: advisory: Initial disclosure by Airbus
- 2026-04-03: patched: Fix made available to customers