A large number of satellite communications systems, even those of military services, are vulnerable to software vulnerabilities that can be exploited by external attackers!
A study by IOActive, which has been made public, clearly states the vulnerabilities in the software of terrestrial satellite communications systems manufactured by giant companies such as Cobham, Harris Corporation, Hughes and Iridium. It seems that the manufacturers of these satellite systems have completely ignored the vulnerabilities that appear in their devices and that can under certain circumstances be subject to remote sabotage - through hacking - by hostile forces, with the aim of interrupting or altering communications.
The systems of the companies mentioned are used in aircraft, ships, military ground units, etc. As experts report, most of the errors are found in the BGAN (Broadband Global Area Network) that manufacturers use with Inmarsat. BGAN is the subsystem that allows network and voice communication for remote units.
The affected Harris terminals are used primarily by the military, including NATO, for tactical radio communications. A hacker could install malware on these devices, pinpoint the soldiers' location, and ultimately disable their tracking systems entirely.
Cobham is a manufacturer of Inmarsat terminals . These are mainly used in shipping, such as the early warning & ship safety system. The weaknesses identified can be used to send false information messages (e.g. false SOS messages) or even change the course of sensitive cargo on a collision course with other passenger ships by sending false data. The use of the weaknesses in the Cobham Aviator systems can endanger aircraft satellite communications (!) but also the ACARS system (announcement and reporting system) which is also found in passenger aircraft. This threat is essentially the most significant, for all civil or military aircraft.
ACARS , etc. A hacker attack on this system could pose a threat to the safety of the entire aircraft!
Of the companies identified with the vulnerabilities, only Iridium has confirmed that it is working to resolve the vulnerabilities. All others declined to comment.
Manufacturers had been notified of vulnerabilities in their devices, vulnerabilities that with a little technical training can be exploited by anyone. See the study below:
[gview file=”Satcom_Security.pdf” save=”0″]
[box_info]
We believe that an IMMEDIATE investigation should be conducted , even in Greece. Security managers of the armed forces, airlines and the powerful shipping industry must know if they have the systems mentioned in the study installed! It is extremely important that national security services and companies have an accurate record of the technologies they use, so that they can be regularly updated and receive-implement critical security upgrades.
[/box_info]



