Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Threats and Vulnerabilities - SQL Injection Vulnerability Could Enable Attackers to Bypass Airport Security
Threats and Vulnerabilities Attacks Critical Infrastructure Security News & Analysis Security

SQL Injection Vulnerability Could Enable Attackers to Bypass Airport Security

ISB Staff ReporterBy ISB Staff ReporterSeptember 2, 2024Updated:November 8, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Airport Security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cybersecurity researchers discovered a vulnerability in the Known Crewmember (KCM) system, a TSA program that allows airline pilots and flight attendants to bypass security screening.

The flaw, which could potentially compromise the safety of millions of air travelers, was found by researchers Ian Carroll and Sam Curry in a system operated by FlyCASS – a service used by smaller airlines to manage KCM and Cockpit Access Security System (CASS) authorizations.

Gaining Administrative Access

KCM and CASS are crucial security programs that streamline airport security checks for airline personnel. KCM enables pilots and flight attendants to bypass regular security lines by verifying their employment status with the airline, while CASS allows authorized pilots to occupy cockpit jumpseats during flights.

Both programs rely on robust employment verification to ensure only active airline employees can use these privileges.

The researchers discovered the vulnerability in FlyCASS, a web-based service used by smaller airlines to manage KCM and CASS authorizations. Upon inspecting the FlyCASS website, they noticed a critical SQL injection flaw. They gained administrative access to Air Transport International’s (ATI) FlyCASS system by entering a simple SQL query into the login page.

Bypassing Stringent Verification Processes

With administrative privileges, the researchers could add unauthorized individuals to the KCM and CASS systems, bypassing the stringent employment verification process. This meant anyone with basic SQL injection knowledge could gain access to restricted airport areas and even cockpits without undergoing security screening.

To test the system, the researchers created a fake employee profile and successfully authorized it for KCM and CASS access. Using FlyCASS’s query features, they confirmed that their test user was approved to bypass security checkpoints and access aircraft cockpits. This glaring vulnerability exposed a significant risk to aviation security, allowing malicious actors to exploit the system easily.

“We’re Taking this Very Seriously”

The researchers promptly reported the vulnerability to the Department of Homeland Security (DHS). The DHS acknowledged the issue, stating they were “taking this very seriously.” FlyCASS was subsequently disabled from participating in KCM and CASS programs, and the vulnerability has since been addressed.

However, the researchers faced challenges in coordinating the disclosure process. Despite their efforts, the TSA press office issued a statement downplaying the severity of the vulnerability, inaccurately claiming that the flaw could not be used to bypass KCM checkpoints.

The researchers countered this claim, pointing out that TSA personnel can manually enter employee IDs, rendering the TSA’s vetting process ineffective in some instances.

The TSA later deleted a section of its website that mentioned the manual input of employee IDs but did not respond to further inquiries from the researchers. The researchers said the TSA’s lack of transparency and communication has raised concerns within the cybersecurity community.

Protecting Transportation

This incident shines a light on the dire need for stronger security measures in systems that protect sensitive areas of transportation infrastructure. The vulnerability in FlyCASS not only jeopardized the integrity of the KCM and CASS programs but also exposed potential gaps in the TSA’s vetting processes.

As cybersecurity threats continue to evolve, robust defenses and timely disclosures are essential to safeguarding public safety. This incident is a stark reminder that even seemingly secure systems can be vulnerable to exploitation, with potentially devastating consequences.

The discovery of this vulnerability highlights the importance of rigorous security testing and transparent communication between researchers and governmental agencies to ensure the traveling public’s safety.

ISB Staff Reporter
  • ISB Staff Reporter
    Mass Exploit Lets Attackers Install Plugins Arbitrarily
  • ISB Staff Reporter
    Cyberattacks Soar 47% Globally – Attacks on Education Increase by 73%
  • ISB Staff Reporter
    CISA Warns of Two Known Exploited Vulnerabilities
  • ISB Staff Reporter
    JFrog Becomes an AI System of Record, Debuts JFrog ML

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read

How EM is boosting the career trajectory of VM analysts

May 19, 20266 Mins Read

Microsoft patches 138 vulnerabilities as AI-driven discovery accelerates

May 14, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}