Research Library / Case Studies /

MedTech / Medical Imaging Equipment

Security Assessment of Critical Healthcare Equipment

One of the largest medical device manufacturers asked Payatu to assess a critical piece of equipment on three fronts: intellectual property, availability and confidentiality. Testing eavesdropped on the firmware upgrade process to recover the device firmware, injected commands over an unauthenticated infrared interface, and found network communication carrying data like X-ray images was not encrypted end to end.
IoT Security Assessment, Firmware Security Assessment, Network Communication Security Assessment

At a glance

INDUSTRY

MedTech / Medical Imaging Equipment

CLIENT PROFILE

One of the largest manufacturers of medical devices

SERVICES

IoT Security Assessment, Firmware Security Assessment, Network Communication Security Assessment

ENGAGEMENT

Assessment across intellectual property, availability and confidentiality risk areas

Key Takeaways

  • Client – One of the largest manufacturers of medical devices, seeking a comprehensive security assessment of a critical piece of medical equipment.

  • Problem – The device needed to be assessed against three risk areas: intellectual property theft of the firmware design, round-the-clock availability without malfunction, and confidentiality of patient data.

  • What Payatu did – Assessed the device's firmware upgrade process, its infrared command interface, and its network communication for weaknesses across IP, availability and confidentiality.

  • Outcome – Found that firmware could be recovered by eavesdropping on the upgrade process, that unauthenticated IR commands could brick the device or alter its configuration, and that network traffic carrying sensitive data was unencrypted.

the challenge

Why the client called us in

None of the client's medical devices, equipment in the same category as MRI and X-ray machines, can afford to malfunction: hospitals need round-the-clock availability, and even a minor glitch can become life-threatening. On top of availability, the client needed assurance that its firmware design couldn't be cloned and that patient data stayed confidential. The client asked Payatu for a comprehensive security assessment covering all three concerns.

  • Ensure the device remains available around the clock without malfunction
  • Prevent duplication of the firmware's design and theft of intellectual property
  • Keep patient data inaccessible to unauthenticated users

scope of engagement

What was in scope

  1. Firmware upgrade (DFU) process assessment
  2. Infrared command interface assessment
  3. Network communication encryption assessment

Our Approach

How Payatu ran the engagement

01

Firmware Upgrade Eavesdropping
Eavesdropped on the device firmware upgrade (DFU) process, capturing network traffic to identify firmware headers and length and recreate the firmware.

02

Infrared Command Injection
Injected commands over the infrared interface from close proximity, exploiting the absence of user authentication to extract device information.

03

Network Communication Analysis
Assessed network interfaces for encryption in transit and found none of the communication to and from the equipment was encrypted end to end.

Key findings

What we found

Firmware Recovery via Eavesdropping
Capturing traffic during the firmware upgrade was enough to identify headers and length and recreate the firmware, exposing the file system, business logic, IP, and credentials to further attacks including backdooring.
Unauthenticated Infrared Command Injection
The infrared interface accepted commands with no authentication, letting a nearby attacker brick the device, alter calibration data, change its Wi-Fi network, or toggle features on and off.
Unencrypted Network Communication
Network traffic to and from the equipment wasn't encrypted end to end, exposing firmware design, X-ray images, business logic, IP, and device credentials to anyone on the network.

the outcome

Results and Impact

Payatu's assessment helped the client mitigate the shortcomings identified across firmware, IR communication and network encryption, shrinking outage windows to a negligible, manageable level for hospital operators.

‍

  • Firmware recovery path via DFU eavesdropping identified and flagged

  • Unauthenticated infrared command injection risk addressed

  • Missing network encryption in transit surfaced for remediation

  • Outage windows reduced to a negligible, manageable level post-assessment

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment