ILT-Interlaboratory Test | Proficiency Testing Provider | Programs
ILT-U-3945

Request Quote

ILT-U-3945

Software and Firmware Security Assessment. Assessment of Competence in the Security Evaluation of Software and Firmware Components of Products with Digital Elements under the Cyber Resilience Act (CRA)

DETERMINATION

METHOD

Hardcoded Administrative CredentialsSource Code Review, Firmware Analysis
Hardcoded Cryptographic KeySource Code Review, Firmware Analysis
Credentials Stored in CleartextConfiguration Review, Data Protection Assessment
Sensitive Information Recorded in LogsLog Analysis, Data Protection Assessment
Insecure Key Management ArchitectureSoftware Architecture Review, Source Code Review
Secure Boot DisabledBootloader Analysis, Configuration Review
Firmware Signature Verification MissingSecure Boot Assessment, Source Code Review
Integrity Failure Does Not Stop ExecutionBoot Process Analysis, Firmware Review
Unsigned Firmware AcceptedFirmware Integrity Assessment, Verification Logic Review
Firmware Downgrade AcceptedUpdate Mechanism Assessment, Configuration Review
Unsigned Update PackageUpdate Package Analysis, Signature Validation Review
Manifest Integrity Not ProtectedManifest Review, Update Security Assessment
Rollback Protection AbsentUpdate Mechanism Assessment, Version Control Review
Update Channel Uses Insecure TransportArchitecture Review, Update Security Assessment
Manifest Validation Logic DeficientSource Code Review, Manifest Analysis
Update Events Not RecordedLog Analysis, Audit Assessment
Log Tampering PossibleLog Repository Review, Configuration Analysis
Log Integrity Controls MissingLogging Architecture Review, Audit Assessment
Audit Trail IncompleteAudit Log Review, Logging Assessment
Administrative Actions Not AuditedAudit Assessment, Log Analysis
Unsafe Function UsageStatic Code Review, Vulnerability Discovery
Known Vulnerable Third-Party ComponentSBOM Analysis, Dependency Review
Insecure Default ConfigurationConfiguration Review, Security Configuration Assessment
Debug Functionality AccessibleSource Code Review, Configuration Analysis
Input Validation WeaknessSource Code Review, Vulnerability Discovery
Security Architecture Design WeaknessSoftware Architecture Review, Trust Boundary Analysis