Skip to content

Security1 publisher2 min readPublished

iDirect iQ-Series terminals return their satellite authentication IDs to unauthenticated callers

ST Engineering's iQ200 answers /api/identity for anyone with network access, handing back the serial number, Device ID and Terminal Private Key identifier that CISA says the platform authenticates with. The fix is 4.5.3.0.

The Watch · Security desk

Illustration accompanying iDirect iQ-Series terminals return their satellite authentication IDs to unauthenticated callers

What happened

  • CISA's advisory covers four CVEs in ST Engineering iDirect iQ-Series terminals, affecting the Evolution iQ-Series, 3315-Series and 9-Series lines at software versions 4.5.2.1 and below.
  • A second defect lets a hostile web page reboot the modem: /api/reboot accepts a POST authorised only by a session cookie with no SameSite attribute, and repeated requests sustain the outage.
  • A third defect escalates privileges locally from the low-privilege field technician account the iQ200 ships with, so an attacker needs no credentials of his own to start.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure On an offshore rig or a vessel where the iQ200 is the only communications link, a sustained reboot loop is the outage, and the trigger is an administrator's browser rather than any credential the attacker holds.
  • contradiction An operator triaging on the summary line reads device-information disclosure plus denial of service; one reading the vulnerability sections finds potential terminal impersonation and local privilege escalation, which is a different priority.
  • constraint Every fallback control CISA offers is network-layer, so a terminal whose management interface stays reachable from an untrusted segment keeps answering the unauthenticated read until the firmware is in.
  • decision Anyone treating the Device ID and TPK as a trust anchor for terminals in defense, energy or transport deployments now has to decide whether an identifier readable over the network still counts as one.

The field in that response is the Terminal Private Key *identifier*, not the private key. CISA enumerates exactly what the endpoint gives up: serial number, Device ID, TPK identifier, MAC address and the exact firmware version [3]. CISA also states that the DID and TPK are what the iDirect platform uses for satellite network authentication, and that holding them potentially enables terminal impersonation and network reconnaissance [4]. That is the advisory's hedge, and the advisory does not describe key material leaving the device or a working impersonation [15]. What an unauthenticated caller reliably gets is a terminal's identity plus a precise firmware fingerprint for whatever comes next.

The three defects sit at different attacker positions. The unauthenticated read needs only network reach to the management interface, and the weakness class is missing authentication for a critical function [3][5]. For the reboot, an attacker has to get a logged-in administrator to load a page he controls: /api/reboot accepts a POST authorised solely by a session cookie with no SameSite attribute and no CSRF token, the satellite link drops immediately, and repeated requests hold it down [6]. Escalation needs a shell, and the iQ200 ships with one, a pre-configured low-privilege field technician account that means nothing has to be brute-forced first [8].

Rank this on the vulnerability sections rather than the summary. The summary scopes impact to unauthorised access to device information or a denial-of-service condition [1]. The sections below it describe potential terminal impersonation and a local privilege escalation on firmware 23.0.1.0 [4][7][14].

ST Engineering iDirect has fixed the vulnerabilities and points registered users to the support portal for 4.5.3.0 or newer [11]. One upgrade from 4.5.2.1 closes all four CVEs across the Evolution iQ-Series, 3315-Series and 9-Series lines [2][13]. Anyone matching builds should note the two version schemes in one document: the escalation is described against firmware 23.0.1.0 while the affected list is written as 4.5.2.1 and below [16]. The four CVE IDs are also listed as a block against every series, so the text does not say which ID is which defect [17].

CISA lists Communications, Defense Industrial Base, Energy, Government Services and Facilities and Transportation Systems among the sectors, with worldwide deployment [10]. Where the iQ200 is the primary and often sole link for an offshore rig, a vessel or a remote site, the CSRF reboot is the defect that shows up in operations first [9]. Until the firmware lands, the controls on offer are network-layer: management interfaces restricted to trusted networks by VPN or ACL, administrative APIs kept off the public internet, and monitoring for anomalous API activity and unexpected reboots [12].

What to watch

  • Whether anyone demonstrates terminal impersonation using only the DID and TPK identifier the endpoint returns.
  • Whether an advisory update maps each of the four CVE IDs to a specific defect, which the current text does not.
  • Scanning counts for iQ-Series management interfaces reachable from the public internet.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories