OmniPump 700 · security posture
Digital twin
| Component | Version | Layer | Open CVEs |
|---|---|---|---|
| openssl | 1.1.1k | crypto | 0 · 3 dismissed |
| linux | 5.10.120 | kernel | 1 conditional |
| busybox | 1.33.1 | userland | 0 · 2 dismissed |
| qt | 5.15.2 | UI | 1 in chain |
| sqlite | 3.36.0 | data | 0 |
| dropbear | 2020.81 | service | 0 · 1 dismissed |
Threat model
| TID | Threat | Twin node | Test cases | Status |
|---|---|---|---|---|
| TID-204 | Untrusted programs access privileged OS functions | Touchscreen Kiosk UI | 31 | realized · root |
| TID-121 | Local privilege escalation via vulnerable service | App Controller | 44 | realized · conditional |
| TID-317 | Weak key derivation exposes stored secrets | Drug Library DB | 18 | realized · conditional |
| TID-208 | Firmware image lacks authenticity verification | Motor Controller | 22 | tested · not realized |
| TID-110 | Cleartext telemetry on hospital network | Comms Gateway | 16 | mitigated · TLS 1.3 |
| TID-402 | BLE pairing accepts unauthenticated peer | Service Interfaces | 12 | tested · not realized |
A high-level model says "the UI is a box." The expanded model knows the kiosk shell, the IPC bus it talks to, the updater it can reach, and the exact process that holds OS access. That resolution is why testing stopped contradicting the model: the model now describes what the testers actually attack.
Test plan & execution
TestLink™ fleet
Findings
| ID | Finding | Component | Isolation CVSS | MDDT · adjusted | Role | Status |
|---|
Exploitable from a known entry vector on its own. These are the roots. Fix these and the chains they feed collapse.
Real, but reachable only while a root keeps producing its enabling condition. Watched, not urgent, and they can flip.
In scope, any CVSS, but no exploit path on this device. Dismissed as Not Affected with reasoning attached, audit ready.
Attack graph
| ID | Finding | Requires → Produces | Isolation · MDDT | Role | Status |
|---|
Releases
| Release | Open direct | Conditional | Weaknesses | Coverage | Submission state |
|---|---|---|---|---|---|
| v2.1.0 | 2 | 27 | 3,904 | 91% | postmarket · patch in flight |
| v2.4.1 | 6 | 19 | 4,187 | 96% | postmarket · current |
| v3.0.0-rc | 0 | 11 | 4,402 | 98% | premarket · 510(k) assembling |
Reports & VEX
510(k) cyber section
SBOM, threat model, enumerated test coverage, control efficacy evidence, and finding history burned down to zero open.
Continuous VEX feed
Per-release VEX status with evidence, MTTT/MTTR metrics, and coordinated disclosure artifacts for HDOs.
CRA / NIS2 timers
4hr AI verification, 24hr early-warning determination, 72hr full report. Timers start on disclosure.