EU Cyber Resilience Act Assessment • 2025-12-11 22:17
The EU Cyber Resilience Act (CRA) establishes cybersecurity requirements for products with digital elements. This assessment evaluates compliance across all Annex I requirements.
| Clause | Requirement | Status |
|---|---|---|
| 1 | Appropriate Cybersecurity Level | Partial |
| 2(a) | No Known Exploitable Vulnerabilities | Non-Compliant |
| 2(b) | Secure by Default Configuration | Partial |
| 2(c) | Security Update Capability | Partial |
| 2(d) | Protection from Unauthorized Access | Partial |
| 2(e) | Data Confidentiality | Partial |
| 2(f) | Data Integrity | Partial |
| 2(g) | Data Minimization | Not Assessed |
| 2(h) | Availability Protection | Partial |
| 2(i) | Minimize Network Impact | Partial |
| 2(j) | Limit Attack Surfaces | Partial |
| 2(k) | Exploitation Mitigation | Compliant |
| 2(l) | Security Logging and Monitoring | Not Assessed |
| 2(m) | Secure Data Removal | Not Assessed |
| Clause | Requirement | Status |
|---|---|---|
| II-1 | SBOM Documentation | Compliant |
| II-2 | Vulnerability Remediation | Compliant |
| II-3 | Regular Security Testing | Compliant |
| II-4 | Vulnerability Disclosure | Compliant |
| II-5 | Coordinated Vulnerability Disclosure Policy | Compliant |
| II-6 | Vulnerability Information Sharing | Compliant |
| II-7 | Secure Update Distribution | Partial |
| II-8 | Security Update Dissemination | Compliant |
Checks Performed:
Score Calculation: Starting from 100 points:
| CISA KEV vulnerabilities (49 found) | -30 pts |
| Config checks failed (6 failed) | -6 pts |
| Cracked credentials (0 found) | No penalty |
| Private keys exposed (24 found) | -20 pts |
| Final Score | 44 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
| CVE | Severity | KEV | Weaponized | EPSS |
|---|---|---|---|---|
| CVE-2016-5195 | HIGH | 🔴 Yes | 💥 Yes | 94.2% |
| CVE-2016-5195 | HIGH | 🔴 Yes | 💥 Yes | 94.2% |
| CVE-2017-1000253 | HIGH | 🔴 Yes | 💥 Yes | 54.4% |
| CVE-2017-1000253 | HIGH | 🔴 Yes | 💥 Yes | 54.4% |
| CVE-2019-13272 | HIGH | 🔴 Yes | 💥 Yes | 80.8% |
| CVE-2021-0920 | MEDIUM | 🔴 Yes | 💥 Yes | 0.9% |
| CVE-2021-0920 | MEDIUM | 🔴 Yes | 💥 Yes | 0.9% |
| CVE-2021-0920 | MEDIUM | 🔴 Yes | 💥 Yes | 0.9% |
| CVE-2021-0920 | MEDIUM | 🔴 Yes | 💥 Yes | 0.9% |
| CVE-2021-22555 | HIGH | 🔴 Yes | 💥 Yes | 86.1% |
Checks Performed:
Score Calculation:
| CISA KEV vulnerabilities (49 found) | Immediate Non-Compliance (0 pts) |
| Weaponized exploits (125 found) | N/A (KEV present) |
| Final Score | 0 pts |
Compliance Logic: Any CISA KEV vulnerability results in immediate non-compliance. Weaponized exploits without KEV entries result in partial compliance (30 pts).
Checks Performed:
Score Calculation: Starting from 100 points:
| Cracked credentials (0 found) | No penalty |
| Critical failed config checks (2 found) | -30 pts |
| Private keys exposed (24 found) | -20 pts |
| Final Score | 50 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
Checks Performed:
Assessment Notes:
NetRise provides vulnerability identification and continuous monitoring capabilities. However, verification of actual update delivery mechanisms requires operational testing outside the scope of static firmware analysis.
Status: Partial - NetRise confirms monitoring capability, but update mechanism verification requires runtime testing.
Checks Performed:
Score Calculation: Starting from 100 points:
| Cracked credentials (0 found) | No penalty |
| Private keys exposed (24 found) | -20 pts |
| Critical vulns >5 (244 found) | -20 pts |
| Final Score | 60 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
Checks Performed:
Score Calculation: Starting from 100 points:
| Certificates with issues (4738 found) | -30 pts |
| Private keys exposed (24 found) | -30 pts |
| Final Score | 40 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
âš 229 vulnerabilities with data integrity CWEs found - Review recommended.
| CVE | Severity | Component | CWEs |
|---|---|---|---|
| CVE-2005-2946 | HIGH | openssl 0.9.7d | CWE-327 |
| CVE-2007-2768 | MEDIUM | openssh 8.0 | CWE-200 |
| CVE-2010-3192 | MEDIUM | glibc 2.23 | CWE-200 |
| CVE-2010-4563 | MEDIUM | linux_kernel 6.6.21 | CWE-200 |
| CVE-2012-4530 | LOW | linux_kernel 3.4.103 | CWE-200 |
| CVE-2012-6536 | LOW | linux_kernel 3.4.103 | CWE-200 |
| CVE-2012-6537 | LOW | linux_kernel 3.4.103 | CWE-200 |
| CVE-2012-6538 | LOW | linux_kernel 3.4.103 | CWE-200 |
| CVE-2012-6539 | LOW | linux_kernel 3.4.103 | CWE-200 |
| CVE-2012-6540 | LOW | linux_kernel 3.4.103 | CWE-200 |
Checks Performed:
Score Calculation:
| 0 data integrity CWEs | 100 pts (Compliant) |
| 1-5 data integrity CWEs | 70 pts (Partial) |
| 6-15 data integrity CWEs | 50 pts (Partial) |
| >15 data integrity CWEs | 30 pts (Non-Compliant) |
| Current (229 CWE matches) | 30 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
Indirect coverage through security risk assessment.
Assessment Status: Not Assessed
Data minimization requirements relate to limiting data collection and processing to what is necessary for the product's intended purpose. This is primarily a design and policy consideration that cannot be fully assessed through static firmware analysis.
Indirect Coverage: NetRise can identify potential data leakage risks through vulnerability analysis, but direct assessment of data minimization practices requires design documentation review.
âš 253 vulnerabilities with DoS-related CWEs found - Review recommended.
| CVE | Severity | Component | CWEs |
|---|---|---|---|
| CVE-2012-0876 | MEDIUM | libexpat 1.95.5 | CWE-400 |
| CVE-2013-7470 | MEDIUM | linux_kernel 3.4.103 | CWE-400 |
| CVE-2014-3122 | MEDIUM | linux_kernel 3.4.103 | CWE-400 |
| CVE-2014-3687 | HIGH | linux_kernel 3.4.103 | CWE-400 |
| CVE-2014-3690 | MEDIUM | linux_kernel 3.14.33 | CWE-400 |
| CVE-2014-7970 | MEDIUM | linux_kernel 3.14.33 | CWE-400 |
| CVE-2014-8559 | MEDIUM | linux_kernel 3.14.33 | CWE-400 |
| CVE-2015-8785 | MEDIUM | linux_kernel 4.1.52 | CWE-835 |
| CVE-2016-6213 | MEDIUM | linux_kernel 3.4.103 | CWE-400 |
| CVE-2016-8666 | HIGH | linux_kernel 3.14.33 | CWE-400 |
Checks Performed:
Score Calculation:
| 0 DoS-related CWEs | 100 pts (Compliant) |
| 1-3 DoS-related CWEs | 70 pts (Partial) |
| 4-10 DoS-related CWEs | 50 pts (Partial) |
| >10 DoS-related CWEs | 30 pts (Non-Compliant) |
| Current (253 CWE matches) | 30 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
Checks Performed:
Assessment Notes:
This clause is assessed in conjunction with Clause 2(h) Availability Protection, as DoS vulnerabilities directly impact network service availability.
Score: 30 pts (based on DoS vulnerability assessment)
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
Checks Performed:
Score Calculation: Starting from 100 points:
| CISA KEV vulnerabilities (49 found) | -30 pts |
| Weaponized exploits (125 found) | -20 pts |
| Large component count (2063 components) | -20 pts |
| Final Score | 30 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
Checks Performed:
Score Calculation: Starting from 100 points:
| Weak/cracked credentials (0 found) | No penalty |
| Exposed private keys (24 found) | -20 pts |
| Final Score | 80 pts |
Status Thresholds: ≥80 = Compliant, 25-79 = Partial, <25 = Non-Compliant
Configuration analysis can be customized to verify logging presence.
Assessment Status: Not Assessed
Security logging and monitoring requirements relate to runtime behavior and operational configuration. Static firmware analysis has limited visibility into logging implementations.
Potential Coverage: Custom configuration checks can be developed to identify presence of logging frameworks, syslog configurations, or audit trails in the firmware image.
Configuration analysis can be customized to verify data removal capability.
Assessment Status: Not Assessed
Secure data removal is primarily a functional capability that requires runtime testing to verify. Static analysis cannot confirm data removal procedures are implemented correctly.
Potential Coverage: Custom configuration checks can identify presence of factory reset mechanisms or data wipe utilities in the firmware.
Checks Performed:
Assessment Logic:
Compliant if components are identified (2063 found). The SBOM provides complete visibility into 2063 software components, with 81 having known vulnerabilities and 1982 (96.1%) being clean.
Checks Performed:
Assessment Logic:
NetRise provides automated vulnerability discovery, prioritization, and remediation guidance. 17740 vulnerabilities tracked, with 54 having known fixes available.
Checks Performed:
Assessment Logic:
NetRise supports integration into development pipelines for regular security testing. Continuous monitoring ensures new vulnerabilities are identified as they are disclosed.
Checks Performed:
Assessment Logic:
NetRise supports VEX document generation for standardized vulnerability disclosure. All 17740 identified vulnerabilities include severity ratings, descriptions, and remediation guidance.
Checks Performed:
Assessment Logic:
NetRise supports coordinated vulnerability disclosure through VEX document generation, enabling standardized communication with stakeholders about vulnerability status and impact.
Checks Performed:
Assessment Logic:
NetRise identifies and tracks 17740 vulnerabilities in third-party components. Reports can be exported in VEX, CycloneDX, and SPDX formats for stakeholder sharing.
Checks Performed:
Assessment Logic:
NetRise provides version tracking and can validate patches through re-analysis. 54 vulnerabilities have known fix versions identified. Status is Partial as actual update distribution mechanisms require operational verification.
Checks Performed:
Assessment Logic:
NetRise supports VEX document generation for security advisory dissemination. Advisories include severity, impact, fix availability, and prioritization data to help users take appropriate action.
Vulnerabilities prioritized by exploitability and impact (showing top 20)
| CVE | Severity | Component | Risk Indicators | EPSS |
|---|---|---|---|---|
| CVE-2023-44487 | HIGH | grpc 0.11.0 | 🔴 KEV 💥 Weaponized | 94.4% |
| CVE-2016-5195 | HIGH | linux_kernel 3.4.103 | 🔴 KEV 💥 Weaponized | 94.2% |
| CVE-2016-5195 | HIGH | linux_kernel 3.14.33 | 🔴 KEV 💥 Weaponized | 94.2% |
| CVE-2024-1086 | HIGH | linux_kernel 5.4.284 | 🔴 KEV 💥 Weaponized | 86.2% |
| CVE-2024-1086 | HIGH | linux_kernel 6.6.21 | 🔴 KEV 💥 Weaponized | 86.2% |
| CVE-2024-1086 | HIGH | linux_kernel 4.1.52 | 🔴 KEV 💥 Weaponized | 86.2% |
| CVE-2021-22555 | HIGH | linux_kernel 4.1.52 | 🔴 KEV 💥 Weaponized | 86.1% |
| CVE-2021-22555 | HIGH | linux_kernel 3.4.103 | 🔴 KEV 💥 Weaponized | 86.1% |
| CVE-2021-22555 | HIGH | linux_kernel 3.14.33 | 🔴 KEV 💥 Weaponized | 86.1% |
| CVE-2019-13272 | HIGH | linux_kernel 4.1.52 | 🔴 KEV 💥 Weaponized | 80.8% |
| CVE-2017-1000253 | HIGH | linux_kernel 3.4.103 | 🔴 KEV 💥 Weaponized | 54.4% |
| CVE-2017-1000253 | HIGH | linux_kernel 3.14.33 | 🔴 KEV 💥 Weaponized | 54.4% |
| CVE-2024-53104 | HIGH | linux_kernel 3.14.33 | 🔴 KEV 💥 Weaponized | 12.0% |
| CVE-2024-53104 | HIGH | linux_kernel 3.4.103 | 🔴 KEV 💥 Weaponized | 12.0% |
| CVE-2024-53104 | HIGH | linux_kernel 5.4.284 | 🔴 KEV 💥 Weaponized | 12.0% |
| CVE-2024-53104 | HIGH | linux_kernel 6.6.21 | 🔴 KEV 💥 Weaponized | 12.0% |
| CVE-2024-53104 | HIGH | linux_kernel 4.1.52 | 🔴 KEV 💥 Weaponized | 12.0% |
| CVE-2022-2586 | HIGH | linux_kernel 3.4.103 | 🔴 KEV 💥 Weaponized | 2.2% |
| CVE-2022-2586 | HIGH | linux_kernel 5.4.284 | 🔴 KEV 💥 Weaponized | 2.2% |
| CVE-2022-2586 | HIGH | linux_kernel 3.14.33 | 🔴 KEV 💥 Weaponized | 2.2% |
Security configuration checks performed: 20 total
| Check | Result | Severity | Details |
|---|---|---|---|
| Multiple users with UID 0 | FAIL | CRITICAL | AUTHENTICATION: Change the UIDs for all other user accounts identified. |
| Users with no password set | FAIL | CRITICAL | AUTHENTICATION: Disable login or set a password for the specified users. |
| World writable and readable directories outside tmp | FAIL | MEDIUM | CONFIGURATION: Modify the permissions to restrict access to the directories. |
| Services Without Configuration Files | FAIL | LOW | CONFIGURATION: Include config files for the associated services to further secure installation. |
| Weak hash algorithms found | FAIL | MEDIUM | CRYPTOGRAPHY: Replace weak hashing algorithms with stronger algorithms. |
| Insecure URL | FAIL | MEDIUM | DATA: Check individual URL problem descriptions |
| Overly permissive access to passwd files | PASS | — | Check passed |
| Authorized Key with Matching Private Key | PASS | — | Check passed |
| History file present on disk | PASS | — | Check passed |
| Sudoers file with weak permissions | PASS | — | Check passed |
| Multiple groups with the same Group ID | PASS | — | Check passed |
| Binaries with Memory Corruption Vulnerabilities and Protection Disabled | PASS | — | Check passed |
| Telnet server exists | PASS | — | Check passed |
| SELinux is disabled | PASS | — | Check passed |
| fstab should always have permissions of 0644 | PASS | — | Check passed |
| Insecure services start at boot | PASS | — | Check passed |
| GTFOBins installed with setuid bit enabled can lead to privilege escalation | PASS | — | Check passed |
| One or more compilers exist | PASS | — | Check passed |
| Sudoers file missing | PASS | — | Check passed |
| Cronjobs with weak permissions | PASS | — | Check passed |
Credentials and password hashes detected in firmware
✓ No password hashes were successfully cracked.
Keys and certificates discovered in firmware
Complete keypairs (matching public and private keys) were found. This means attackers can extract both keys and fully impersonate the device or decrypt its communications.
Embedded private keys can be extracted and used to compromise encrypted communications or impersonate the device.
Generated by NetRise Platform • 2025-12-11 22:17
This report provides an assessment of CRA compliance based on NetRise platform analysis.