
ILT-U-3938
Consumer IoT Product Security Assessment. Assessment of Competence in the Security Evaluation of Products with Digital Elements under the Cyber Resilience Act (CRA)
DETERMINATION | METHOD |
| Exposed Administrative Interface | Documentation Review, Architecture Analysis, Service Enumeration |
| Undocumented Management Service | Firmware Analysis, Port Enumeration, Documentation Review |
| Exposed Debug Endpoint | API Analysis, API Enumeration, Documentation Review |
| Development API Available in Production | API Testing, Endpoint Enumeration |
| Excessive API Exposure | API Analysis, Attack Surface Assessment |
| Weak Password Policy | Authentication Assessment, Configuration Review |
| Default Credentials Present | Authentication Testing, Configuration Review |
| Weak Session Management | Session Analysis, Authentication Testing |
| Insufficient Account Lockout Controls | Authentication Testing, Brute Force Assessment |
| Insecure Password Reset Process | Functional Testing, Authentication Workflow Analysis |
| Horizontal Privilege Escalation | Authorization Testing, API Testing |
| Unauthorized Resource Access | Access Control Testing, Authorization Assessment |
| Missing Authorization Check | Functional Testing, API Assessment |
| API Authorization Failure | Authorization Testing, API Security Assessment |
| Excessive Default Privileges | Role Analysis, Authorization Assessment |
| Deprecated Cryptographic Algorithm | Cryptographic Review, Firmware Analysis |
| Hardcoded Cryptographic Key | Firmware Analysis, Application Analysis, Configuration Review |
| Predictable Random Number Generation | Cryptographic Analysis, Code Review |
| Weak Certificate Validation | Application Analysis, Communication Security Assessment |
| Secrets Stored in Cleartext | Configuration Review, Firmware Analysis |
| Weak TLS Configuration | Communication Security Assessment, Protocol Analysis |
| Protocol Downgrade Vulnerability | Communication Testing, Protocol Analysis |
| Certificate Validation Failure | Communication Security Assessment, Application Analysis |
| Unencrypted Sensitive Communications | Traffic Analysis, API Testing, Communication Security Assessment |
| Sensitive Metadata Exposure | API Analysis, Traffic Analysis, Response Inspection |

