ELTONPLATFORM
OmniPump 700 Infusion System
Meridian BioSystems · Class II cyber device · demo tenant
DEMO DATA · FICTIONAL PRODUCT
System of record · postmarket + premarket

OmniPump 700 · security posture

Everything below is computed from the release twin: findings, exploitability, ratings, coverage, and the evidence trail behind each number.
v2.4.1● TWIN IN SYNC
6
Direct · fix now
Exploitable from the attack surface
19
Conditional · watch
Alive only while a root produces access
4,187
Weaknesses · proven inert
No path, evidence attached, no action
96%
Attack surface coverage
1,847 test cases enumerated
Triage automationMDDT criteria
Auto-triaged this quarter412 / 448 · 92%
MTTT · mean time to triage1.4 days
MTTR · mean time to resolve8.6 days
Untriaged past SLA0
Every rating carries rubric rationale, generated at triage time
Verification mixL1 / L2 / L3
L1 · twin analysis1,912 dispositions
L2 · code + firmware1,406 dispositions
L3 · real hardware exploit attempt869 dispositions
Not Affected rate at L381%
Deeper access, higher dismissal confidence
Live activitySERVER + BENCH
14:02:11 CVE CVE-2026-13377 matched · openssl 1.1.1k
14:02:14 TEST TC-1339 selected · exploit PoC
14:07:40 RESULT not exploitable from tested access
14:07:41 VEX status → Not Affected · evidence attached
14:07:41 GRAPH chaining analysis recomputed
Compliance snapshot · FDA 524BAUDIT READY
SBOM · CycloneDX✓ current
Vulnerability process✓ evidenced
Coordinated disclosure✓ on file
Postmarket plan✓ continuous
Model · per release

Digital twin

Architecture, software materials, interfaces, controls, and initial access vectors for v2.4.1. Seeded from documentation, verified by scanning and on-device testing.
214 COMPONENTS5 INTERFACES7 CONTROLS
ARCHITECTURE · TRUST BOUNDARIES DASHED · CONTROLS ◉ · IAV ▶ TB-1 · USER ZONE Touchscreen Kiosk UI Qt 5.15 · kiosk shell ◉ kiosk lockdown ▶ IAVtouch App Controller Linux 5.10 SoC · 214 pkgs ◉ signed updates · ◉ SELinux SBOM: openssl · busybox · sqlite… Drug Library DB sqlite 3.36 · dose limits ◉ PHI encryption at rest Pump Motor Controller RTOS firmware · dose engine ◉ secure boot · ◉ cmd allowlist TB-2 · THERAPY ZONE · SAFETY CRITICAL Comms Gateway HL7 out · MQTT cloud ◉ TLS 1.3 egress Service Interfaces USB service · BLE pairing ▶ IAV usb (latent) · ▶ IAV ble Hospital Network Ethernet · HL7 listener ▶ IAV network JTAG / debug not exposed on production C-jtag has no producer Every finding, threat, and test case below binds to a node in this model. Change the release and the twin changes with it.
The release twin: components, boundaries (dashed), documented controls (◉) overlaid where they live, and initial access vectors (▶) that seed the attack graph.
Software materials · SBOM214 COMPONENTS · CYCLONEDX
ComponentVersionLayerOpen CVEs
openssl1.1.1kcrypto0 · 3 dismissed
linux5.10.120kernel1 conditional
busybox1.33.1userland0 · 2 dismissed
qt5.15.2UI1 in chain
sqlite3.36.0data0
dropbear2020.81service0 · 1 dismissed
Security profileCONTROLS + CONDITIONS
Documented controls, overlaid7 · all test-planned
Trust boundaries3 · user / therapy / cloud
Initial access vectors4 active · 1 latent
Conditions tracked in graphC-os-access · C-admin · C-dbhash · C-jtag…
Twin provenancedocs + scan + runtime verified
Medical protocol contextHL7 · MQTT
Model · expanded on the twin

Threat model

Your documented model had 8 system-level threats. ELTON consumed it, overlaid it on the twin, and expanded it to 87 process-level threats, each mapped to EMB3D and to test cases. Model and testing stay in sync.
8 AUTHORED87 EXPANDED0 DRIFT
87
Threats enumerated
Per process, not per box
10x
Vs a human model
Static scans + real runtime access
100%
Threats with test cases
Nothing modeled goes untested
3
Threats realized
Testing confirmed exploit path
Threat registerEMB3D-MAPPED · CLICK A REALIZED THREAT
TIDThreatTwin nodeTest casesStatus
TID-208Firmware image lacks authenticity verificationMotor Controller22tested · not realized
TID-110Cleartext telemetry on hospital networkComms Gateway16mitigated · TLS 1.3
TID-402BLE pairing accepts unauthenticated peerService Interfaces12tested · not realized
Why expansion matters

A high-level model says "the UI is a box." The expanded model knows the kiosk shell, the IPC bus it talks to, the updater it can reach, and the exact process that holds OS access. That resolution is why testing stopped contradicting the model: the model now describes what the testers actually attack.

Discover · all sources, one pipeline

Test plan & execution

Every cybersecurity test case launched against the product scope: pentest, SAST, DAST, fuzzing, SBOM CVE PoC. Enumerated coverage is the premarket deliverable, even where no finding exists.
1,847
Test cases
Enumerated to scope
1,782
Passed
Control held / not exploitable
57
Weak / partial
Efficacy gap logged
8
Failed · finding raised
Routed to Findings
Coverage by sourceCONTROL + THREAT DRIVEN
Penetration testing (expert + AI)612
SAST · source & build438
DAST · live interface341
Fuzzing · protocol/input268
SBOM CVE proof-of-concept188
Live test executionIDLE
Test caseTC-1339 · openssl CVE PoC
Target nodeApp Controller · Comms Gateway
AccessL3 · TestLink™ on device
Press "Run test case TC-1339" to attempt exploitation.
Discover · self-directed, on your bench

TestLink™ fleet

Three appliances give the OmniPump team their own pentesting capability. Cable to the device, map physical ports to twin components, push the button. Same harness, developer's hands.
2 CONNECTED1 SYNCING
tbox-0001● CONNECTED
BenchMeridian Lab A
TwinOmniPump v2.4.1
Linkout-of-band 5G
ETH↔HL7USB↔servicerunning 44 TC
tbox-0002● CONNECTED
BenchMeridian Lab A
TwinOmniPump v3.0.0-rc
Linkout-of-band 5G
BLE↔pairingidle · paired
tbox-0003▲ SYNCING
BenchContract mfr · Denver
TwinOmniPump v2.1.0
Linkcfg drift v5→v7
△ unpairedupdating agent
tbox-0001 · operator → DUT ops flowRESULTS STREAM TO PLATFORM
OPERATOR● consolepush a test plan ELTON PLATFORM● plan from twinTC-1301…TC-1344 TestLink™ tbox-0001● black box applianceETH·USB·BLE·SER OmniPump 700 · DUT● live sourcev2.4.1 on the bench FINDINGS + EVIDENCE● results stream inTC result · VEX · log PHYSICAL PORT MAPETH→HL7 iface · USB→service port
Verify · true positives only

Findings

Rated with the FDA MDDT rubric first, then classified by exploitability against this release. Click any finding for the full evidence trail, VEX status, and remediation guidance.
6 DIRECT19 CONDITIONAL4,187 WEAKNESS
Root & realized findings · OmniPump v2.4.1CLICK A ROW
IDFindingComponentIsolation CVSSMDDT · adjustedRoleStatus
Direct · red

Exploitable from a known entry vector on its own. These are the roots. Fix these and the chains they feed collapse.

Conditional · amber

Real, but reachable only while a root keeps producing its enabling condition. Watched, not urgent, and they can flip.

Weakness · green

In scope, any CVSS, but no exploit path on this device. Dismissed as Not Affected with reasoning attached, audit ready.

Verify · the graph decides

Attack graph

Entry vectors produce conditions. Findings need conditions. A finding is a vulnerability only while every precondition is produced upstream. Fix the kiosk root and watch the OS chain become weaknesses on the fly.
4
Vulnerabilities · affected
1
Weaknesses · not_affected
0
Roots fixed
5
Findings in this chain
▶ INITIAL ACCESSTouchscreen UI ROOT · VULNF2 · Kiosk breakoutMDDT 8.4 · CVE-2026-QT · isolation 7.6 DERIV · VULNF4 · Local privescSBOM CVE · isolation 7.8 High DERIV · VULNF5 · Read drug-lib DBisolation 6.5 Med DERIV · VULNF6 · Weak KDF secretsisolation 9.1 Critical WEAKNESS · ALWAYSF7 · Firmware signingisolation 8.2 · C-jtag unmet no producer for C-jtag on this release C-touch C-os C-admin C-dbhash Kiosk root is live. C-os is produced, so every OS finding downstream is an exploitable vulnerability.
Isolation scores never move; they stay intact for compliance. Only status recomputes. One fix retires four findings' worth of action.
Chain findingsSTATUS RECOMPUTES LIVE
IDFindingRequires → ProducesIsolation · MDDTRoleStatus
Prove · every commercial release, separately

Releases

FDA requires each commercialized release managed on its own. The same CVE lands three different ways here, because each answer is computed against that release's own twin.
CVE-2026-13377 · openssl 9.8
v2.1.0AFFECTED
Fielded2023 · 4,100 units
Twinopenssl 1.1.1k on exposed HL7
Chains withlocal privesc finding
MDDT8.1 · patch required
VEX: Affected
v2.4.1NOT AFFECTED
Fielded2025 · 9,800 units
Twinlistener bound to localhost
Mitigationshipped in v2.4
EvidenceL3 exploit failed
VEX: Not Affected
v3.0.0-rcCONDITIONAL
Status2026 · premarket
Twinopenssl upgraded · new BLE
Notenot vulnerable · new surface watched
MDDTmonitored
VEX: Under Investigation
Release-to-release carry-overMTTT / MTTR TRACKED PER RELEASE
ReleaseOpen directConditionalWeaknessesCoverageSubmission state
v2.1.02273,90491%postmarket · patch in flight
v2.4.16194,18796%postmarket · current
v3.0.0-rc0114,40298%premarket · 510(k) assembling
Prove · evidence as a byproduct

Reports & VEX

Every test, verification, and fix confirmation generates the audit trail automatically. VEX in CycloneDX, MDDT-rated scores, and the enumerated coverage a reviewer expects, carrying the ELTON brand and FDA approved vendor credentials.
FDA 524B premarket

510(k) cyber section

SBOM, threat model, enumerated test coverage, control efficacy evidence, and finding history burned down to zero open.

✓ ready
Postmarket surveillance

Continuous VEX feed

Per-release VEX status with evidence, MTTT/MTTR metrics, and coordinated disclosure artifacts for HDOs.

✓ streaming
Incident response

CRA / NIS2 timers

4hr AI verification, 24hr early-warning determination, 72hr full report. Timers start on disclosure.

retainer active
VEX statement · CVE-2026-13377 · v2.4.1CYCLONEDX · AUTO-GENERATED
// generated by ELTON · MDDT methodology · FDA approved vendor { "bomFormat": "CycloneDX", "specVersion": "1.5", "vulnerabilities": [{ "id": "CVE-2026-13377", "affects": [{ "ref": "OmniPump-700@v2.4.1" }], "ratings": [{ "method": "CVSSv4", "score": 2.1, "source": "ELTON-MDDT" }], "analysis": { "state": "not_affected", "justification": "protected_by_mitigating_control", "detail": "HL7 listener bound to localhost in v2.4; L3 exploit attempt TC-1339 failed. Evidence: run log 2026-07-17." } }] }
STEP 1 / 14