ILT-Interlaboratory Test | Proficiency Testing Provider | Programs
ILT-U-3938

Request Quote

ILT-U-3938

Consumer IoT Product Security Assessment. Assessment of Competence in the Security Evaluation of Products with Digital Elements under the Cyber Resilience Act (CRA)

DETERMINATION

METHOD

Exposed Administrative InterfaceDocumentation Review, Architecture Analysis, Service Enumeration
Undocumented Management ServiceFirmware Analysis, Port Enumeration, Documentation Review
Exposed Debug EndpointAPI Analysis, API Enumeration, Documentation Review
Development API Available in ProductionAPI Testing, Endpoint Enumeration
Excessive API ExposureAPI Analysis, Attack Surface Assessment
Weak Password PolicyAuthentication Assessment, Configuration Review
Default Credentials PresentAuthentication Testing, Configuration Review
Weak Session ManagementSession Analysis, Authentication Testing
Insufficient Account Lockout ControlsAuthentication Testing, Brute Force Assessment
Insecure Password Reset ProcessFunctional Testing, Authentication Workflow Analysis
Horizontal Privilege EscalationAuthorization Testing, API Testing
Unauthorized Resource AccessAccess Control Testing, Authorization Assessment
Missing Authorization CheckFunctional Testing, API Assessment
API Authorization FailureAuthorization Testing, API Security Assessment
Excessive Default PrivilegesRole Analysis, Authorization Assessment
Deprecated Cryptographic AlgorithmCryptographic Review, Firmware Analysis
Hardcoded Cryptographic KeyFirmware Analysis, Application Analysis, Configuration Review
Predictable Random Number GenerationCryptographic Analysis, Code Review
Weak Certificate ValidationApplication Analysis, Communication Security Assessment
Secrets Stored in CleartextConfiguration Review, Firmware Analysis
Weak TLS ConfigurationCommunication Security Assessment, Protocol Analysis
Protocol Downgrade VulnerabilityCommunication Testing, Protocol Analysis
Certificate Validation FailureCommunication Security Assessment, Application Analysis
Unencrypted Sensitive CommunicationsTraffic Analysis, API Testing, Communication Security Assessment
Sensitive Metadata ExposureAPI Analysis, Traffic Analysis, Response Inspection