Gray Box Pentest for a Pharma Company Revealed Severe Intranet Vulnerabilities

Gray Box Pentest for a Pharma Company Revealed Severe Intranet Vulnerabilities

Industry
Healthcare, Life Sciences, Manufacturing

Summary

A US bioscience company providing drug testing, formulation development, and solid-dose manufacturing wanted to verify the cyber protection of its private network but lacked in-house cybersecurity expertise. INNERLUXES performed gray-box penetration testing of the 49-IP network, uncovered seven security issues (three of them high-severity), and delivered a comprehensive remediation report in five days that raised the intranet's security level from low to high.

About the Customer

The Customer is a US bioscience company providing drug testing, formulation development, and solid-dose manufacturing services for pharmaceutical and biotech companies.

The Challenge

The Customer wanted to verify the cyber protection of its private network. Due to a lack of in-house cybersecurity expertise, the company was looking for a trustworthy and experienced vendor to spot potential vulnerabilities.

The Solution

Based on a careful analysis of the Customer's security needs, INNERLUXES selected the gray-box pentesting approach (imitating the actions of a real-life attacker who has partial access to the targets).

The Customer provided low-privileged user credentials to access its network, which comprised 49 IP addresses. The pentesters started with a vulnerability assessment: they scanned the network using automated tools and manually validated the results. After excluding false positives, the team attempted to exploit the found vulnerabilities and gain higher-level access to the system and sensitive data. During the pentest, INNERLUXES followed PTES and NIST 800-115 best practices.

Using the NIST CVSS threat-classification standard, INNERLUXES's cybersecurity experts assessed the found vulnerabilities by exploitation likelihood and potential impact, identifying three high-severity, one medium-severity, and three low-severity security issues. These included:

  • The use of default administrator credentials that allowed any user on the local network to access and control the intranet devices.
  • An access-control vulnerability that allowed an attacker to exploit the SMB (Server Message Block) protocol for DoS attacks or the distribution of malicious files.
  • Outdated software components with multiple known vulnerabilities that could allow disclosure of sensitive data, DoS attacks, privilege escalation, and execution of arbitrary code.

To fix these issues, the team recommended the following steps:

  • Implementing a stronger password policy to prevent the use of default credentials and blank or weak passwords on network devices.
  • Setting up strict access controls by using read-only permissions on the server side and moving servers that require read/write permission to another isolated VLAN.
  • Updating software to the latest version.

The Results

  • In just five days, INNERLUXES's pentesters verified the Customer's private network and drew up a comprehensive report describing the testing activities, the found vulnerabilities, and corresponding corrective actions.
  • Following the remediation advice, the Customer fixed all identified issues and raised the security level of its intranet from low to high — confirmed by a retest.

Technologies and Tools

Metasploit, Nessus, Acunetix, smbclient, CrackMapExec, Nmap, Python, C, Perl.