The Pump on the Guest Network
Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.
Three days into a hospital engagement, I carried my laptop to the cafeteria and joined the guest Wi-Fi like any visitor would. A quick scan showed it touched a subnet I wasn’t expecting: a long-forgotten handful of networked infusion pumps. The automated tooling on the job hadn’t flagged the reach, because the pumps themselves weren’t vulnerable. Their existence wasn’t a bug. A scanner has no way to know that a guest network should never be able to reach a device that delivers medication.
That is the gap. A scanner can fingerprint that pump and catalog every known flaw in its software. What it cannot grasp is the organizational impact of configuration drift, the slow accumulation of small changes that had quietly left a life-critical device one hop from the coffee line.
The pump’s management interface answered on port 80, a local login that had never been tied to the device-based authentication the staff used everywhere else. A quick search turned up the vendor’s default credentials. Someone had changed them, but the replacement turned out to be the hospital’s own name. Someone’s tomorrow was hanging on that network, a keystroke away.
I stopped testing and called the client’s security team directly. A scanner would have filed this as a low: an old web login on an old device. In context, it was the most critical thing on the engagement. I will not claim we saved a life that afternoon. But I know we didn’t cost anyone theirs.