Interactive demo

Drive the platform yourself. No sales call required.

This is a click-through of the real ELTON workflow on a fictional infusion pump, the OmniPump 700. Walk the digital twin, the threat model, autonomous testing, exploitability verification, the vulnerability graph, TestLink™, release management, and VEX reporting. Every number and finding is demo data. Take the guided tour or wander.

ELTONPLATFORM
OmniPump 700 Infusion System
Meridian BioSystems · Class II cyber device · demo tenant
DEMO DATA · FICTIONAL PRODUCT
System of record · postmarket + premarket

OmniPump 700 · security posture

Everything below is computed from the release twin: findings, exploitability, ratings, coverage, and the evidence trail behind each number.
v2.4.1● TWIN IN SYNC
6
Direct · fix now
Exploitable from the attack surface
19
Conditional · watch
Alive only while a root produces access
4,187
Weaknesses
Exploitable due to other direct vulnerabilities
96%
Attack surface coverage
1,847 test cases enumerated
Triage automationMDDT criteria
Auto-triaged this quarter412 / 448 · 92%
MTTT · mean time to triage1.4 days
MTTR · mean time to resolve8.6 days
Untriaged past SLA0
Every rating carries rubric rationale, generated at triage time
Verification mixL1 / L2 / L3
L1 · twin analysis1,912 dispositions
L2 · code + firmware1,406 dispositions
L3 · real hardware exploit attempt869 dispositions
Not Affected rate at L381%
Deeper access, higher dismissal confidence
Live activitySERVER + BENCH
14:02:11 CVE CVE-2026-13377 matched · openssl 1.1.1k
14:02:14 TEST TC-1339 selected · exploit PoC
14:07:40 RESULT not exploitable from tested access
14:07:41 VEX status → Not Affected · evidence attached
14:07:41 GRAPH chaining analysis recomputed
TestLink™ fleet · agentic pentesters-in-a-boxOUT-OF-BAND 5G
ELTON TESTLINK FLEETLIVEout-of-band 5G · northbound REST6/7UMRs online3appliances2live sessions45msRTT p50FLEET DEPLOYMENTStbox-0001CONNECTEDAcme Corp · v7 · livetbox-0002CONNECTEDAcme Corp · v9 · idletbox-0003DEGRADEDNorthwind · cfg drift v5→v77 remote units · 2 paired · click a box to dive inDEPLOYMENT GRIDsites 6 · units 7ELTON CONSOLESeattleoffline×2LabonlineFielddegradedChicagoonlineDenveronlineDallasonlineonlinedegradedoffline
Model · per release

Digital twin

Architecture, software materials, interfaces, controls, and initial access vectors for v2.4.1. Seeded from documentation, verified by scanning and on-device testing.
214 COMPONENTS5 INTERFACES7 CONTROLS
ARCHITECTURE · TRUST BOUNDARIES DASHED · CONTROLS ◉ · IAV ▶ TB-1 · USER ZONE Touchscreen Kiosk UI Qt 5.15 · kiosk shell ◉ kiosk lockdown ▶ IAVtouch App Controller Linux 5.10 SoC · 214 pkgs ◉ signed updates · ◉ SELinux SBOM: openssl · busybox · sqlite… Drug Library DB sqlite 3.36 · dose limits ◉ PHI encryption at rest Pump Motor Controller RTOS firmware · dose engine ◉ secure boot · ◉ cmd allowlist TB-2 · THERAPY ZONE · SAFETY CRITICAL Comms Gateway HL7 out · MQTT cloud ◉ TLS 1.3 egress Service Interfaces USB service · BLE pairing ▶ IAV usb (latent) · ▶ IAV ble Hospital Network Ethernet · HL7 listener ▶ IAV network JTAG / debug not exposed on production C-jtag has no producer Every finding, threat, and test case below binds to a node in this model. Change the release and the twin changes with it.
The release twin: components, boundaries (dashed), documented controls (◉) overlaid where they live, and initial access vectors (▶) that seed the attack graph.
Software materials · SBOM214 COMPONENTS · CYCLONEDX
ComponentVersionLayerOpen CVEs
openssl1.1.1kcrypto0 · 3 dismissed
linux5.10.120kernel1 conditional
busybox1.33.1userland0 · 2 dismissed
qt5.15.2UI1 in chain
sqlite3.36.0data0
dropbear2020.81service0 · 1 dismissed
Security profileCONTROLS + CONDITIONS
Documented controls, overlaid7 · all test-planned
Trust boundaries3 · user / therapy / cloud
Initial access vectors4 active · 1 latent
Conditions tracked in graphC-os-access · C-admin · C-dbhash · C-jtag…
Twin provenancedocs + scan + runtime verified
Medical protocol contextHL7 · MQTT
Model · expanded on the twin

Threat model

Your documented model had 8 system-level threats. ELTON consumed it, overlaid it on the twin, and expanded it to 87 process-level threats, each mapped to EMB3D and to test cases. Model and testing stay in sync.
8 AUTHORED87 EXPANDED0 DRIFT
87
Threats enumerated
Per process, not per box
10x
Vs a human model
Static scans + real runtime access
100%
Threats with test cases
Nothing modeled goes untested
3
Threats realized
Testing confirmed exploit path
Threat registerEMB3D-MAPPED · CLICK A REALIZED THREAT
TIDThreatTwin nodeTest casesStatus
TID-208Firmware image lacks authenticity verificationMotor Controller22tested · not realized
TID-110Cleartext telemetry on hospital networkComms Gateway16mitigated · TLS 1.3
TID-402BLE pairing accepts unauthenticated peerService Interfaces12tested · not realized
Why expansion matters

A high-level model says "the UI is a box." The expanded model knows the kiosk shell, the IPC bus it talks to, the updater it can reach, and the exact process that holds OS access. That resolution is why testing stopped contradicting the model: the model now describes what the testers actually attack.

Discover · all sources, one pipeline

Test plan & execution

Every cybersecurity test case launched against the product scope: pentest, SAST, DAST, fuzzing, SBOM CVE PoC. Enumerated coverage is the premarket deliverable, even where no finding exists.
1,847
Test cases
Enumerated to scope
1,782
Passed
Control held / not exploitable
57
Weak / partial
Efficacy gap logged
8
Failed · finding raised
Routed to Findings
Coverage by sourceCONTROL + THREAT DRIVEN
Penetration testing (expert + AI)612
SAST · source & build438
DAST · live interface341
Fuzzing · protocol/input268
SBOM CVE proof-of-concept188
Live test executionIDLE
Test caseTC-1339 · openssl CVE PoC
Target nodeApp Controller · Comms Gateway
AccessL3 · TestLink™ on device
Press "Run test case TC-1339" to attempt exploitation.
Discover · self-directed, on your bench

TestLink™ fleet

Three appliances give the OmniPump team their own pentesting capability. Cable to the device, map physical ports to twin components, push the button. Same harness, developer's hands.
2 CONNECTED1 SYNCING
tbox-0001● CONNECTED
BenchMeridian Lab A
TwinOmniPump v2.4.1
Linkout-of-band 5G
ETH↔HL7USB↔servicerunning 44 TC
tbox-0002● CONNECTED
BenchMeridian Lab A
TwinOmniPump v3.0.0-rc
Linkout-of-band 5G
BLE↔pairingidle · paired
tbox-0003▲ SYNCING
BenchContract mfr · Denver
TwinOmniPump v2.1.0
Linkcfg drift v5→v7
△ unpairedupdating agent
tbox-0001 · operator → DUT ops flowRESULTS STREAM TO PLATFORM
OPERATOR● consolepush a test plan ELTON PLATFORM● plan from twinTC-1301…TC-1344 TestLink™ tbox-0001● black box applianceETH·USB·BLE·SER OmniPump 700 · DUT● live sourcev2.4.1 on the bench FINDINGS + EVIDENCE● results stream inTC result · VEX · log PHYSICAL PORT MAPETH→HL7 iface · USB→service port
Fleet map · all benches2/3 ONLINE · OUT-OF-BAND 5G
ELTON TESTLINK FLEETLIVEout-of-band 5G · northbound REST2/3units online3appliances1live session41msRTT p50 · bench linkFLEET DEPLOYMENTStbox-0001CONNECTEDMeridian Lab A · v2.4.1 · 44 TC livetbox-0002CONNECTEDMeridian Lab A · v3.0.0-rc · idletbox-0003SYNCINGContract mfr · Denver · drift v5→v73 appliances · 2 paired · click a box to inspectDEPLOYMENT GRIDsites 2 · units 3ELTON CONSOLE×2Meridian Lab A41ms · onlineContract mfr · Denver— · syncingonlinesyncing
Verify · true positives only

Findings

Rated with the FDA MDDT rubric first, then classified by exploitability against this release. Click any finding for the full evidence trail, VEX status, and remediation guidance.
6 DIRECT19 CONDITIONAL4,187 WEAKNESS
Root & realized findings · OmniPump v2.4.1CLICK A ROW
IDFindingComponentIsolation CVSSMDDT · adjustedRoleStatus
Direct · red

Exploitable from a known entry vector on its own. These are the roots. Fix these and the chains they feed collapse.

Conditional · amber

Real, but reachable only while a root keeps producing its enabling condition. Watched, not urgent, and they can flip.

Weakness · green

In scope, any CVSS, but no exploit path on this device. Dismissed as Not Affected with reasoning attached, audit ready.

Verify · the graph decides

Attack graph

Entry vectors produce conditions. Findings need conditions. A finding is a vulnerability only while every precondition is produced upstream. Fix the kiosk root and watch the OS chain become weaknesses on the fly.
4
Vulnerabilities · affected
1
Weaknesses · not_affected
0
Roots fixed
5
Findings in this chain
▶ INITIAL ACCESSTouchscreen UI ROOT · VULNF2 · Kiosk breakoutMDDT 8.4 · CVE-2026-QT · isolation 7.6 DERIV · VULNF4 · Local privescSBOM CVE · isolation 7.8 High DERIV · VULNF5 · Read drug-lib DBisolation 6.5 Med DERIV · VULNF6 · Weak KDF secretsisolation 9.1 Critical WEAKNESS · ALWAYSF7 · Firmware signingisolation 8.2 · C-jtag unmet no producer for C-jtag on this release C-touch C-os C-admin C-dbhash Kiosk root is live. C-os is produced, so every OS finding downstream is an exploitable vulnerability.
Isolation scores never move; they stay intact for compliance. Only status recomputes. One fix retires four findings' worth of action.
Chain findingsSTATUS RECOMPUTES LIVE
IDFindingRequires → ProducesIsolation · MDDTRoleStatus
Prove · every commercial release, separately

Releases

FDA requires each commercialized release managed on its own. The same CVE lands three different ways here, because each answer is computed against that release's own twin.
CVE-2026-13377 · openssl 9.8
v2.1.0AFFECTED
Fielded2023 · 4,100 units
Twinopenssl 1.1.1k on exposed HL7
Chains withlocal privesc finding
MDDT8.1 · patch required
VEX: Affected
v2.4.1NOT AFFECTED
Fielded2025 · 9,800 units
Twinlistener bound to localhost
Mitigationshipped in v2.4
EvidenceL3 exploit failed
VEX: Not Affected
v3.0.0-rcCONDITIONAL
Status2026 · premarket
Twinopenssl upgraded · new BLE
Notenot vulnerable · new surface watched
MDDTmonitored
VEX: Under Investigation
Release-to-release carry-overMTTT / MTTR TRACKED PER RELEASE
ReleaseOpen directConditionalWeaknessesCoverageSubmission state
v2.1.02273,90491%postmarket · patch in flight
v2.4.16194,18796%postmarket · current
v3.0.0-rc0114,40298%premarket · 510(k) assembling
Prove · evidence as a byproduct

Reports & VEX

Every test, verification, and fix confirmation generates the audit trail automatically. VEX in CycloneDX, MDDT-rated scores, and the enumerated coverage a reviewer expects, carrying the ELTON brand and FDA approved vendor credentials.
FDA 524B premarket

510(k) cyber section

SBOM, threat model, enumerated test coverage, control efficacy evidence, and finding history burned down to zero open.

✓ ready
Postmarket surveillance

Continuous VEX feed

Per-release VEX status with evidence, MTTT/MTTR metrics, and coordinated disclosure artifacts for HDOs.

✓ streaming
Incident response

CRA / NIS2 timers

4hr AI verification, 24hr early-warning determination, 72hr full report. Timers start on disclosure.

retainer active
VEX statement · CVE-2026-13377 · v2.4.1CYCLONEDX · AUTO-GENERATED
// generated by ELTON · MDDT methodology · FDA approved vendor { "bomFormat": "CycloneDX", "specVersion": "1.5", "vulnerabilities": [{ "id": "CVE-2026-13377", "affects": [{ "ref": "OmniPump-700@v2.4.1" }], "ratings": [{ "method": "CVSSv4", "score": 2.1, "source": "ELTON-MDDT" }], "analysis": { "state": "not_affected", "justification": "protected_by_mitigating_control", "detail": "HL7 listener bound to localhost in v2.4; L3 exploit attempt TC-1339 failed. Evidence: run log 2026-07-17." } }] }
STEP 1 / 14

Best experienced on a desktop screen. The product, findings, and figures shown are fictional and illustrative. What you see is how ELTON actually works: model the device, test it, chain the findings, and evidence every verdict.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo