1. Review the product documentation, component inventory, bill of materials, or equivalent information to identify the elements contained in the product (which may include software, firmware, or hardware elements, as applicable) and their relevant versions or patch levels, where available.
2. Perform vulnerability scanning, where technically feasible, on the product or relevant components to identify candidate vulnerabilities affecting elements contained in the product.
1. Review the product documentation, component inventory, bill of materials, or equivalent information to identify the components contained in the product (which may include software, firmware, or hardware components, as applicable) and their relevant versions or patch levels, where available.
2. Perform vulnerability scanning, where technically feasible, on the product or relevant components to identify candidate vulnerabilities affecting the product.
3. Assess, in accordance with prEN 40000-1-3 [i.6], the vulnerabilities identified through correlation of scanning results, product identification information, vendor advisories, and recognized public vulnerability sources.
4. For each identified known exploitable vulnerability, review the vulnerability assessment and verify whether it demonstrates that the vulnerability is not exploitable in the product:
5. Where the treatment of an identified known exploitable vulnerability relies on user guidance, review the user guidance and verify that it specifically addresses the conditions to prevent exploitation.