Case Study | Pharmaceutical | HITEC City, Hyderabad | VAPT
VAPT for a Hyderabad Pharmaceutical Company — 47 Vulnerabilities Found and Fixed
How MDIT Services conducted a comprehensive Vulnerability Assessment and Penetration Testing (VAPT) engagement for a Hyderabad-based pharmaceutical exporter, identifying 47 vulnerabilities including 3 critical-severity findings — and supporting full remediation to secure a critical EU partnership.
- 47 vulnerabilities identified across all VAPT scope areas
- 3 Critical findings → 0 after remediation and verified re-test
- 12 High findings → 0 within 30 days of report delivery
- EU partner relationship secured — clinical trial data access granted
- Annual VAPT contract signed following engagement success
The Client and the Challenge
The client is a mid-size pharmaceutical company based in HITEC City, Hyderabad, with 1,200 employees and a significant export business to the EU and US markets. The company manufactures generic pharmaceuticals and active pharmaceutical ingredients (APIs), and had recently entered into preliminary discussions with a European pharmaceutical research organisation about sharing access to a clinical trial data management platform.
The EU partner’s IT security team issued a clear pre-condition before any data-sharing integration could proceed: the Indian company must provide a current, comprehensive VAPT report demonstrating that their external-facing systems, internal network, web applications, APIs, and Active Directory environment had been professionally tested for vulnerabilities.
The pharmaceutical company had never undergone a formal VAPT. Their IT security posture had grown organically over the years — functional, but unaudited. The CTO was uncertain what a VAPT would find and equally uncertain about what to do if serious vulnerabilities were discovered.
MDIT was engaged to conduct the VAPT, deliver a professional report that would satisfy the EU partner’s security team, and provide hands-on remediation guidance to close any findings discovered.
VAPT Scope
MDIT and the client agreed on the following VAPT scope, covering all systems that the EU partner’s security team had identified as relevant to the data integration:
- External Network VAPT: All internet-facing IP addresses and subdomains associated with the company’s primary domain — including the main website, customer portal, partner portal, and email gateway.
- Internal Network VAPT: The HITEC City head office internal network, covering approximately 180 servers and network devices, tested from an authenticated internal position simulating a compromised employee workstation.
- Web Application Testing (3 Applications):
- External partner portal (used by EU and US partners for order management and documentation exchange)
- Internal enterprise resource planning (ERP) application web interface
- Quality management system (QMS) web application (ISO 9001 and regulatory documentation)
- API Security Testing: The REST API layer connecting the partner portal to the company’s ERP system — the API that the EU partner’s platform would integrate with.
- Active Directory Security Audit: Assessment of the on-premises Active Directory environment for common misconfigurations, privilege escalation paths, Kerberos attack vectors (Kerberoasting, AS-REP roasting), and lateral movement opportunities.
Testing was conducted as a grey-box assessment — MDIT was provided with application credentials and network diagrams but approached systems as an attacker would, without access to source code. A rules of engagement document was agreed before testing commenced, defining safe testing boundaries and an emergency stop procedure.
Key Findings — 47 Vulnerabilities Identified
MDIT’s VAPT team identified a total of 47 vulnerabilities across all scope areas:
| Severity | Count | CVSS Score Range |
|---|---|---|
| Critical | 3 | 9.0 – 10.0 |
| High | 12 | 7.0 – 8.9 |
| Medium | 22 | 4.0 – 6.9 |
| Low | 10 | 0.1 – 3.9 |
| Total | 47 |
Critical Finding 1 — Unpatched RCE on External-Facing Server (CVSS 9.8)
An external-facing server running a document management application was found running an unpatched version of a widely deployed Java framework with a publicly known Remote Code Execution (RCE) vulnerability — CVE assigned, CVSS base score 9.8. Exploitation of this vulnerability would allow an unauthenticated attacker to execute arbitrary code on the server with the privileges of the web application service account.
This server was reachable from the internet. Given the attacker’s ability to then pivot to the internal network from this server, the impact was classified as critical. MDIT demonstrated proof-of-concept exploitation in the controlled testing environment (without accessing or modifying production data) to confirm exploitability.
Critical Finding 2 — SQL Injection in Partner Portal (CVSS 9.4)
The external partner portal contained a SQL injection vulnerability in the order search functionality. MDIT’s web application testing team demonstrated that this vulnerability allowed extraction of the entire partner database — including partner contact information, order history, and confidential pricing agreements — without authentication. The same vulnerability could be used to write data to the database.
This finding was particularly significant given that the EU partner was being offered access to exactly this portal — a company that had conducted a security review of the portal before accepting access would immediately have identified this vulnerability through basic testing.
Critical Finding 3 — Active Directory Misconfiguration Enabling Domain Escalation (CVSS 9.1)
The Active Directory audit identified a misconfigured service account with unconstrained Kerberos delegation rights. An attacker with access to any machine in the domain to which this service account authenticated could capture the Kerberos Ticket Granting Ticket (TGT) of any user — including Domain Administrators — authenticating to that machine. Combined with the ability to compromise a single standard user workstation, this misconfiguration provided a reliable path to full Domain Administrator privilege within the environment.
The Active Directory audit also identified 14 additional high-severity misconfigurations including: AdminSDHolder propagation issues, excessive privileged group membership, Kerberoastable service accounts with weak passwords, and AS-REP roastable user accounts.
High and Medium Severity Findings (Sample)
- Outdated and vulnerable SSL/TLS certificates on 4 external-facing services
- HTTP security headers missing (CSP, HSTS, X-Frame-Options) across all 3 web applications
- API authentication tokens transmitted without expiry configuration (JWT without expiration claim)
- Verbose error messages exposing internal file paths and software version information
- Internal file shares accessible to all domain users (no need-to-know access controls)
- SMB signing not enforced (enabling man-in-the-middle and NTLM relay attacks)
- Password policy not enforced via Group Policy (some accounts with passwords under 8 characters)
- Default credentials found on 2 internal network devices (management interfaces)
Remediation Support and Re-Test
MDIT provided a detailed remediation guide alongside the vulnerability report — for each finding, the guide included a technical explanation of the vulnerability, step-by-step remediation instructions (not generic advice), and links to relevant vendor patches, security advisories, and configuration guides.
MDIT’s consultants were available by phone and email throughout the remediation period to answer technical questions from the client’s IT team. For the three critical findings, MDIT consultants joined video calls with the IT team to walk through remediation steps in real time.
All 3 critical findings and all 12 high findings were remediated and verified via MDIT re-test within 30 days of report delivery. The re-test confirmed that each finding was fully resolved. A re-test certificate documenting the verified status of all findings was issued.
The 22 medium findings were remediated over the subsequent 60 days, with MDIT conducting a final verification re-test at Day 90.
Results
The VAPT report — accompanied by the re-test certificate confirming remediation of all critical and high findings — was submitted to the EU partner’s IT security team. The report was accepted without further queries within five business days. The clinical trial data integration was approved to proceed, unlocking the partnership that had been contingent on the security assessment.
The VAPT exercise also had a significant internal impact: the pharmaceutical company’s leadership team, previously unaware of the severity of their security posture, approved a structured annual security programme. MDIT was engaged on an annual VAPT contract, complemented by quarterly vulnerability scanning of external-facing assets and security awareness training for all 1,200 employees.
“We were completely unprepared for what MDIT found. Three critical vulnerabilities — one of which meant anyone on the internet could have taken over our server. We’re fortunate that MDIT found these before a real attacker did. The EU partnership is now live, and we have an ongoing programme in place so we never find ourselves in this position again.”
Related MDIT Services
- Vulnerability Assessment & Penetration Testing — Comprehensive VAPT services for pharmaceutical and life sciences companies
- Web Application Penetration Testing — In-depth testing of web applications, APIs, and portals
- Cybersecurity for Healthcare — Specialised security for healthcare and pharmaceutical organisations
