@@ -1382,14 +1382,14 @@ The assessment criteria for each security requirements are described in a struct
- REFERENCE: ACC-PKI-KEV-01
- OBJECTIVE: Verify that:
1. Known exploitable vulnerabilities affecting the product are identified.
2. For each identified known exploitable vulnerability, one of the following applies:
the vulnerability assessment demonstrates that the vulnerability is not exploitable in the product; or
- Known exploitable vulnerabilities affecting the product are identified.
- For each identified known exploitable vulnerability, one of the following applies:
-the vulnerability assessment demonstrates that the vulnerability is not exploitable in the product; or
specific user guidance is provided to prevent exploitation.
3. No known exploitable vulnerability remains in the product without one of the above justifications.
- No known exploitable vulnerability remains in the product without one of the above justifications.
- PREPARATION:
-[DESIGN] Product documentation identifying elements contained in the product (elements may include software, firmware, or hardware elements, as applicable).
-[INVENTORY] component inventory, bill of materials, or equivalent software identification information, including version and patch-level information where available.
- Product documentation identifying elements contained in the product (elements may include software, firmware, or hardware elements, as applicable).
-Component inventory, bill of materials, or equivalent software identification information, including version and patch-level information where available.
- Access to the product, or to relevant components such as binaries, packages, images, firmware, containers, or file systems, sufficient to perform vulnerability scanning where technically feasible.
- Vulnerability scanning tools and associated vulnerability databases suitable for identifying candidate vulnerabilities in the product.
- Access to recognized public vulnerability sources:
@@ -1408,10 +1408,10 @@ The assessment criteria for each security requirements are described in a struct
- Pass: Known exploitable vulnerabilities affecting the product are identified, and each such vulnerability is covered either by a vulnerability assessment demonstrating non-exploitability in the product, or by specific user guidance preventing exploitation.
- Fail: Vulnerability assessment is missing or insufficient for one or more such vulnerabilities, user guidance is missing or inadequate where relied upon, or one or more known exploitable vulnerabilities remain without justified treatment.
- EVIDENCE:
-[SCAN] Vulnerability scanning results, including the tools and vulnerability databases used.
-[ADVISORY] Recognized public vulnerability sources, vendor advisories, and product identification information used in the assessment.
-[ANALYSIS] Vulnerability assessment records and conclusions produced in accordance with prEN 40000-1-3 [X].
-[GUIDANCE] Product user guidance relied upon to prevent exploitation, where applicable.
- Vulnerability scanning results, including the tools and vulnerability databases used.
- Recognized public vulnerability sources, vendor advisories, and product identification information used in the assessment.
- Vulnerability assessment records and conclusions produced in accordance with prEN 40000-1-3 [X].
- Product user guidance relied upon to prevent exploitation, where applicable.