/
    Zpět na blog
    Security

    Researchers find SQL injection to bypass airport TSA security checks


    Researchers find SQL injection to bypass airport TSA security checks

    image

    Security researchers Ian Carroll and Sam Curry have identified an exploit in a key air transport security system, FlyCASS, that could potentially allow unauthorized individuals to bypass airport security checks and gain unsanctioned access to airplane cockpits.

    The vulnerability was observed in the management of the Known Crewmember (KCM) and Cockpit Access Security System (CASS) programs — services used by several airlines to expedite the security process for crew members. The KCM system, operated by Collins Aerospace subsidiary ARINC, verifies crew members’ credentials online, negating the need for physical screening. Similarly, the CASS system verifies pilots looking to access cockpit jumpseats when commuting or traveling.

    The flaw in the system was found to be susceptible to SQL injection, a form of cyberattack that enables the attacker to influence database queries with malicious SQL statements. The researchers exploited this flaw to log into the FlyCASS system as an administrator for Air Transport International, a participating airline, and manipulated internal employee data. They added an imaginary employee, “Test TestOnly”, and granted it access to the KCM and CASS programs, thus granting the potential to bypass security and access aircraft cockpits.

    Recognizing the gravity of their findings, the researchers notified the Department of Homeland Security (DHS) about the vulnerability on April 23, 2024. In response, the DHS acknowledged the seriousness of the vulnerability and detached FlyCASS from the KCM/CASS systems on May 7, 2024, as a precaution. Subsequently, the flaw in FlyCASS was patched. Despite this, the DHS halted further correspondence regarding the issue. The TSA press office issued a statement downplaying the concern, claiming its vetting process would prevent unauthorized access, but also removed contradictory information from their website following the researchers’ discovery.

    Subsequent to the researchers’ disclosure, another researcher, Alesandro Ortiz, found that FlyCASS appeared to have suffered a ransomware attack earlier in the year, in February 2024. Commenting on the issue, TSA press secretary R. Carter Langston informed BleepingComputer that “No government data or systems were compromised and there are no transportation security impacts related to the activities.” Langston added that the TSA did not rely solely on the compromised database to verify the identity of crewmembers, assuring that the TSA was working to mitigate any identified cyber vulnerabilities. The DHS has yet to comment.

    © 2026 Patrik Žák. Všechna práva vyhrazena.