Coverage · FDIE
Firmware coverage, with the boundaries in view.
Understand which image families and analysis methods FDIE can examine, what each result can support, and where further assessment is needed. Qualify your exact firmware, packaging and engine build before relying on a workflow.
- 60
- Unique technical checks in the source suite
- 11
- Published framework mapping profiles
- Per image
- Compatibility and execution coverage
Images and artifacts
Compatibility starts with the actual image.
Support depends on packaging, available metadata and the selected analysis mode. Recognising a container or processor is a starting point. It does not guarantee that every region can be extracted, every function decompiled or every binary executed.
| Surface | Examples and scope | Compatibility boundary |
|---|---|---|
| Containers and filesystems | Embedded Linux images, vendor update wrappers, raw images and nested archives. SquashFS, UBI/UBIFS, JFFS2, CramFS, RomFS, ext2/3/4 and FAT12/16/32 families. | Custom layouts, unsupported compression and damaged images can require preparation. Recognition does not establish complete extraction. |
| Encrypted regions | Supported schemes with available, lawfully obtained key material. | Unknown encrypted regions remain unreadable. Do not send private keys through marketing or support forms. |
| Binary review | Recovered ELF and PE metadata, linking, strings, disassembly and supported function analysis. | Stripped or statically linked binaries and proprietary naming can reduce identification and function matching. |
| Emulation | Supported CPU, ABI and userspace combinations for Linux binaries on MIPS, ARM, AArch64 and x86-64. Full system boot runs only where the deployment provides a compatible kernel. | Drivers, peripherals, missing libraries and custom hardware can prevent execution even when the CPU is recognised. |
| MCU and RTOS images | Recoverable metadata and supported static checks. | Do not assume full-system runtime coverage or transfer a Linux qualification result to an MCU or RTOS image. |
Analysis scope
Different methods answer different questions.
Follow the evidence from recovered artifacts to findings, runtime observations and release decisions. Review unsupported and failed stages alongside successful ones; a completed job does not imply complete security coverage.
| Review area | Available evidence | What still needs review |
|---|---|---|
| Components and vulnerabilities | Recognised software, available versions, linking metadata and advisory matches with severity, EPSS and KEV context. | Identification and feed age affect results. A version match does not establish reachability or account for every vendor backport. |
| Credentials, cryptography and hardening | Recoverable credential candidates, cryptographic usage, binary protections, update mechanisms and secure-boot indicators. | Static indicators cannot establish hardware enforcement, effective device configuration or the absence of unrecognised secrets. |
| Scripts and attack surface | Supported shipped-script checks, recovered configuration, service evidence and YARA indicators. | A match requires investigation. Unrecovered files and unrecognised patterns remain outside the observed scope. |
| Release and function comparison | Added, removed and changed components, available binary/function evidence and earlier triage suggestions for analyst review. | Compare extraction, engine and feed context on both releases. A changed function or hash alone does not prove remediation. |
| Runtime and fuzzing | Bounded per-binary emulation, process and socket observations, and candidate crashes from supported targets; full system boot only where a compatible kernel is provided. | Coverage is limited to the executed paths, inputs and time budget. Reproduce crashes and distinguish firmware faults from environment failures. |
| Framework evidence and exports | Mapped technical checks, supported software and cryptographic inventories, recorded vulnerability dispositions and assessment reports. | Exports retain the assessment's limits. Hardware assurance, organisational processes and legal applicability require additional evidence and review. |
Read the result
Keep assessment gaps in the release record.
Status describes what happened during the assessment. It should travel with the findings, inventory and analyst decision, including any follow-up testing.
- Complete
- The job reached its completion state. Check the individual stages and targets before concluding which surfaces were assessed.
- Partial
- Some evidence is available, while other stages or regions could not be assessed. Retain both the findings and the reasons for incomplete work.
- Unassessed
- An evidence gap remains. This is not a pass, a clean result or a not-affected vulnerability disposition.
- Source inventory
- A published set of configured capabilities and mappings. It does not prove that a particular deployed release enabled or executed every check.
Framework mapping inventory
Inspect the checks behind each profile.
This source inventory was reviewed on 16 September 2026. Its 60 unique technical checks are mapped to 11 profiles. A check can appear in more than one profile, so profile totals must not be added together as unique checks.
Mappings identify technical references, not certification or a guarantee of the checks enabled in a deployed release. Some references address a broad mechanism family. Assess the relevant edition, product applicability and missing hardware or organisational evidence separately. CRA disclosure review is a separate workflow.
OWASP Firmware Security Testing Methodology1.0 · 47 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | Stage 5 |
| TC-CRED-03 · Password hash strength assessment | Credential Security | Stage 5 |
| TC-CRED-04 · API key and token detection | Credential Security | Stage 5 |
| TC-CRED-05 · Embedded private key detection | Credential Security | Stage 5 |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | Stage 5 |
| TC-CRED-07 · Account with no password set | Credential Security | Stage 5 |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | Stage 5 |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | Stage 5 |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | Stage 5 |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | Stage 5 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | Stage 5 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | Stage 5 |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | Stage 5 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | Stage 5 |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | Stage 5 |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | Stage 5 |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | Stage 5 |
| TC-BIN-01 · Stack canary detection | Binary Hardening | Stage 5 |
| TC-BIN-02 · NX/DEP bit verification | Binary Hardening | Stage 5 |
| TC-BIN-03 · PIE/ASLR verification | Binary Hardening | Stage 5 |
| TC-BIN-04 · RELRO configuration | Binary Hardening | Stage 5 |
| TC-BIN-05 · Debug symbol stripping | Binary Hardening | Stage 5 |
| TC-BIN-06 · Insecure RPATH/RUNPATH | Binary Hardening | Stage 5 |
| TC-ATK-01 · Telnet service detection | Attack Surface | Stage 5 |
| TC-ATK-02 · FTP service detection | Attack Surface | Stage 5 |
| TC-ATK-03 · Debug tool presence | Attack Surface | Stage 5 |
| TC-ATK-04 · UART debug shell detection | Attack Surface | Stage 5 |
| TC-ATK-06 · Web interface privilege check | Attack Surface | Stage 5 |
| TC-CVE-01 · OS and kernel CVE scan | Known Vulnerabilities | Stage 5 |
| TC-CVE-02 · BusyBox CVE scan | Known Vulnerabilities | Stage 5 |
| TC-CVE-03 · TLS library CVE check | Known Vulnerabilities | Stage 5 |
| TC-CVE-05 · Known vulnerable binary hash match | Known Vulnerabilities | Stage 5 |
| TC-CVE-06 · Firmware-wide critical CVE presence | Known Vulnerabilities | Stage 5 |
| TC-CVE-07 · CVE regression from prior firmware version | Known Vulnerabilities | Stage 5 |
| TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVE | Known Vulnerabilities | Stage 5 |
| TC-CVE-09 · End-of-life component in the SBOM | Known Vulnerabilities | Stage 5 |
| TC-RUN-01 · Memory-safety fault under adversarial input | Runtime Behaviour | Stage 7 |
| TC-RUN-02 · Network-reachable command execution surface | Runtime Behaviour | Stage 7 |
| TC-ATK-08 · Brute-force protection on network authentication | Attack Surface | Stage 5 |
| TC-ATK-09 · Pre-authentication information disclosure | Attack Surface | Stage 5 |
| TC-ATK-10 · Redundant root-privileged account | Attack Surface | Stage 5 |
| TC-ATK-11 · Security event logging present | Attack Surface | Stage 5 |
| TC-ATK-12 · Management interface served over cleartext HTTP | Attack Surface | Stage 5 |
| TC-CODE-01 · Command or code injection in shipped scripts | Code Security | Stage 5 |
| TC-CODE-02 · Untrusted input rendered by the device web interface | Code Security | Stage 5 |
| TC-CODE-03 · Untrusted input selects a file path | Code Security | Stage 5 |
| TC-CODE-04 · Untrusted data parsed by an interpreter or database | Code Security | Stage 5 |
NIST SP 800-193Final · 9 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-UPD-01 · Update signature verification presence | Firmware Update | 4.1.2 |
| TC-UPD-03 · Rollback protection | Firmware Update | 4.1.3 |
| TC-UPD-04 · Pre-installation integrity check | Firmware Update | 4.1.2 |
| TC-UPD-05 · Unsigned update rejection | Firmware Update | 4.1.1 |
| TC-ATK-11 · Security event logging present | Attack Surface | 4.1.4 |
| TC-BOOT-01 · Bootloader signature verification | Secure Boot | 4.1.1 |
| TC-BOOT-02 · Boot measurement capability | Secure Boot | 4.2.3 |
| TC-BOOT-03 · Recovery partition presence | Secure Boot | 4.3.1 |
| TC-BOOT-04 · Runtime integrity verification | Secure Boot | 4.2.1 |
ETSI EN 303 645v2.1.1 · 44 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | 5.1-1 |
| TC-CRED-02 · Default credential database match | Credential Security | 5.1-1, 5.1-2 |
| TC-CRED-03 · Password hash strength assessment | Credential Security | 5.4 |
| TC-CRED-05 · Embedded private key detection | Credential Security | 5.4 |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | 5.4-1 |
| TC-CRED-07 · Account with no password set | Credential Security | 5.1-1 |
| TC-UPD-01 · Update signature verification presence | Firmware Update | 5.3-3 |
| TC-UPD-02 · Update channel encryption | Firmware Update | 5.3-2 |
| TC-UPD-04 · Pre-installation integrity check | Firmware Update | 5.3-3 |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | 5.5 |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | 5.5 |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | 5.5 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | 5.5 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | 5.5 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | 5.5 |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | 5.5 |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | 5.5 |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | 5.5 |
| TC-ATK-01 · Telnet service detection | Attack Surface | 5.6-1 |
| TC-ATK-02 · FTP service detection | Attack Surface | 5.6 |
| TC-ATK-03 · Debug tool presence | Attack Surface | 5.6-2 |
| TC-ATK-04 · UART debug shell detection | Attack Surface | 5.6 |
| TC-ATK-05 · Unnecessary network services | Attack Surface | 5.6-1 |
| TC-ATK-06 · Web interface privilege check | Attack Surface | 5.6-3 |
| TC-ATK-07 · Vulnerability disclosure policy presence | Attack Surface | 5.2 |
| TC-CVE-01 · OS and kernel CVE scan | Known Vulnerabilities | 5.3 |
| TC-CVE-02 · BusyBox CVE scan | Known Vulnerabilities | 5.3 |
| TC-CVE-03 · TLS library CVE check | Known Vulnerabilities | 5.3 |
| TC-CVE-04 · SBOM generation | Known Vulnerabilities | 5.3 |
| TC-CVE-06 · Firmware-wide critical CVE presence | Known Vulnerabilities | 5.3 |
| TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVE | Known Vulnerabilities | 5.3 |
| TC-CVE-09 · End-of-life component in the SBOM | Known Vulnerabilities | 5.3 |
| TC-RUN-01 · Memory-safety fault under adversarial input | Runtime Behaviour | 5.13-1 |
| TC-RUN-02 · Network-reachable command execution surface | Runtime Behaviour | 5.13-1 |
| TC-ATK-08 · Brute-force protection on network authentication | Attack Surface | 5.1-5 |
| TC-ATK-09 · Pre-authentication information disclosure | Attack Surface | 5.6-2 |
| TC-ATK-10 · Redundant root-privileged account | Attack Surface | 5.6-3 |
| TC-ATK-12 · Management interface served over cleartext HTTP | Attack Surface | 5.5-1 |
| TC-CODE-01 · Command or code injection in shipped scripts | Code Security | 5.13-1 |
| TC-CODE-02 · Untrusted input rendered by the device web interface | Code Security | 5.13-1 |
| TC-CODE-03 · Untrusted input selects a file path | Code Security | 5.13-1 |
| TC-CODE-04 · Untrusted data parsed by an interpreter or database | Code Security | 5.13-1 |
| TC-BOOT-01 · Bootloader signature verification | Secure Boot | 5.7 |
| TC-BOOT-04 · Runtime integrity verification | Secure Boot | 5.7 |
NIST IR 8259AFinal · 17 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | Capability 4 |
| TC-CRED-02 · Default credential database match | Credential Security | Capability 2 |
| TC-CRED-07 · Account with no password set | Credential Security | Capability 4 |
| TC-UPD-01 · Update signature verification presence | Firmware Update | Capability 5 |
| TC-UPD-02 · Update channel encryption | Firmware Update | Capability 5 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | Capability 3 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | Capability 3 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | Capability 3 |
| TC-ATK-01 · Telnet service detection | Attack Surface | Capability 4 |
| TC-ATK-05 · Unnecessary network services | Attack Surface | Capability 4 |
| TC-CVE-01 · OS and kernel CVE scan | Known Vulnerabilities | Capability 5 |
| TC-CVE-04 · SBOM generation | Known Vulnerabilities | Capability 6 |
| TC-CVE-06 · Firmware-wide critical CVE presence | Known Vulnerabilities | Capability 5 |
| TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVE | Known Vulnerabilities | Capability 5 |
| TC-CVE-09 · End-of-life component in the SBOM | Known Vulnerabilities | Capability 5 |
| TC-ATK-08 · Brute-force protection on network authentication | Attack Surface | Capability 4 |
| TC-ATK-12 · Management interface served over cleartext HTTP | Attack Surface | Capability 3 |
IEC 62443-4-22019 · 36 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | CR 1.5 |
| TC-CRED-02 · Default credential database match | Credential Security | CR 1.1 |
| TC-CRED-03 · Password hash strength assessment | Credential Security | CR 1.5 |
| TC-CRED-04 · API key and token detection | Credential Security | CR 1.5 |
| TC-CRED-05 · Embedded private key detection | Credential Security | CR 1.5 |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | CR 4.1 |
| TC-CRED-07 · Account with no password set | Credential Security | CR 1.5 |
| TC-UPD-01 · Update signature verification presence | Firmware Update | CR 3.4 |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | CR 4.1 |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | CR 4.1 |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | CR 4.1 |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | CR 4.1 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | CR 4.1 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | CR 4.1 |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | CR 4.1 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | CR 4.1 |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | CR 4.1 |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | CR 4.1 |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | CR 4.1 |
| TC-ATK-01 · Telnet service detection | Attack Surface | CR 2.1 |
| TC-ATK-02 · FTP service detection | Attack Surface | CR 2.1 |
| TC-ATK-03 · Debug tool presence | Attack Surface | CR 2.1 |
| TC-ATK-04 · UART debug shell detection | Attack Surface | CR 2.1 |
| TC-ATK-05 · Unnecessary network services | Attack Surface | CR 2.1 |
| TC-ATK-06 · Web interface privilege check | Attack Surface | CR 2.1 |
| TC-RUN-01 · Memory-safety fault under adversarial input | Runtime Behaviour | CR 3.5 |
| TC-RUN-02 · Network-reachable command execution surface | Runtime Behaviour | CR 3.5 |
| TC-ATK-08 · Brute-force protection on network authentication | Attack Surface | CR 1.11 |
| TC-ATK-10 · Redundant root-privileged account | Attack Surface | CR 2.1 |
| TC-ATK-11 · Security event logging present | Attack Surface | CR 6.1 |
| TC-ATK-12 · Management interface served over cleartext HTTP | Attack Surface | CR 4.1 |
| TC-CODE-01 · Command or code injection in shipped scripts | Code Security | CR 3.5 |
| TC-CODE-02 · Untrusted input rendered by the device web interface | Code Security | CR 3.5 |
| TC-CODE-03 · Untrusted input selects a file path | Code Security | CR 3.5 |
| TC-CODE-04 · Untrusted data parsed by an interpreter or database | Code Security | CR 3.5 |
| TC-BOOT-01 · Bootloader signature verification | Secure Boot | CR 3.4 |
EN 18031-12024 · 45 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | AUM-1 |
| TC-CRED-02 · Default credential database match | Credential Security | AUM-1 |
| TC-CRED-03 · Password hash strength assessment | Credential Security | AUM-1 |
| TC-CRED-04 · API key and token detection | Credential Security | AUM-1 |
| TC-CRED-05 · Embedded private key detection | Credential Security | AUM-1 |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | AUM-1 |
| TC-CRED-07 · Account with no password set | Credential Security | AUM-1 |
| TC-UPD-01 · Update signature verification presence | Firmware Update | SUM-1 |
| TC-UPD-02 · Update channel encryption | Firmware Update | SUM-1 |
| TC-UPD-03 · Rollback protection | Firmware Update | SUM-1 |
| TC-UPD-04 · Pre-installation integrity check | Firmware Update | SUM-1 |
| TC-UPD-05 · Unsigned update rejection | Firmware Update | SUM-1 |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | CRY-1 |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | CRY-1 |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | CRY-1 |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | CRY-1 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | CRY-1 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | CRY-1 |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | CRY-1 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | CRY-1 |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | CRY-1 |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | CRY-1 |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | CRY-1 |
| TC-BIN-01 · Stack canary detection | Binary Hardening | GEC-1 |
| TC-BIN-02 · NX/DEP bit verification | Binary Hardening | GEC-1 |
| TC-BIN-03 · PIE/ASLR verification | Binary Hardening | GEC-1 |
| TC-BIN-04 · RELRO configuration | Binary Hardening | GEC-1 |
| TC-BIN-05 · Debug symbol stripping | Binary Hardening | GEC-1 |
| TC-BIN-06 · Insecure RPATH/RUNPATH | Binary Hardening | GEC-1 |
| TC-ATK-01 · Telnet service detection | Attack Surface | GEC-2 |
| TC-ATK-02 · FTP service detection | Attack Surface | GEC-2 |
| TC-ATK-03 · Debug tool presence | Attack Surface | GEC-2 |
| TC-ATK-04 · UART debug shell detection | Attack Surface | GEC-2 |
| TC-ATK-05 · Unnecessary network services | Attack Surface | GEC-2 |
| TC-ATK-06 · Web interface privilege check | Attack Surface | GEC-2 |
| TC-ATK-07 · Vulnerability disclosure policy presence | Attack Surface | GEC-2 |
| TC-ATK-08 · Brute-force protection on network authentication | Attack Surface | GEC-2 |
| TC-ATK-09 · Pre-authentication information disclosure | Attack Surface | GEC-2 |
| TC-ATK-10 · Redundant root-privileged account | Attack Surface | GEC-2 |
| TC-ATK-11 · Security event logging present | Attack Surface | GEC-2 |
| TC-ATK-12 · Management interface served over cleartext HTTP | Attack Surface | GEC-2 |
| TC-BOOT-01 · Bootloader signature verification | Secure Boot | RLM-1 |
| TC-BOOT-02 · Boot measurement capability | Secure Boot | RLM-1 |
| TC-BOOT-03 · Recovery partition presence | Secure Boot | RLM-1 |
| TC-BOOT-04 · Runtime integrity verification | Secure Boot | RLM-1 |
EN 18031-22024 · 18 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | SSM-1 |
| TC-CRED-02 · Default credential database match | Credential Security | SSM-1 |
| TC-CRED-03 · Password hash strength assessment | Credential Security | SSM-1 |
| TC-CRED-04 · API key and token detection | Credential Security | SSM-1 |
| TC-CRED-05 · Embedded private key detection | Credential Security | SSM-1 |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | SSM-1 |
| TC-CRED-07 · Account with no password set | Credential Security | SSM-1 |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | SCM-1 |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | SCM-1 |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | SCM-1 |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | SCM-1 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | SCM-1 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | SCM-1 |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | SCM-1 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | SCM-1 |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | SCM-1 |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | SCM-1 |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | SCM-1 |
EN 18031-32024 · 23 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | RED 3.3(f) - AUM |
| TC-CRED-02 · Default credential database match | Credential Security | RED 3.3(f) - AUM |
| TC-CRED-03 · Password hash strength assessment | Credential Security | RED 3.3(f) - AUM |
| TC-CRED-04 · API key and token detection | Credential Security | RED 3.3(f) - AUM |
| TC-CRED-05 · Embedded private key detection | Credential Security | RED 3.3(f) - AUM |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | RED 3.3(f) - AUM |
| TC-CRED-07 · Account with no password set | Credential Security | RED 3.3(f) - AUM |
| TC-UPD-01 · Update signature verification presence | Firmware Update | RED 3.3(f) - SUM |
| TC-UPD-02 · Update channel encryption | Firmware Update | RED 3.3(f) - SUM |
| TC-UPD-03 · Rollback protection | Firmware Update | RED 3.3(f) - SUM |
| TC-UPD-04 · Pre-installation integrity check | Firmware Update | RED 3.3(f) - SUM |
| TC-UPD-05 · Unsigned update rejection | Firmware Update | RED 3.3(f) - SUM |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-06 · Certificate validation | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | RED 3.3(f) - CRY |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | RED 3.3(f) - CRY |
IEC 81001-5-12021 · 39 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | 5.2.2 |
| TC-CRED-02 · Default credential database match | Credential Security | 5.2.2 |
| TC-CRED-03 · Password hash strength assessment | Credential Security | 5.2.2 |
| TC-CRED-04 · API key and token detection | Credential Security | 5.2.2 |
| TC-CRED-05 · Embedded private key detection | Credential Security | 5.2.2 |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | 5.2.2 |
| TC-CRED-07 · Account with no password set | Credential Security | 5.2.2 |
| TC-UPD-01 · Update signature verification presence | Firmware Update | 7.2 |
| TC-UPD-02 · Update channel encryption | Firmware Update | 7.2 |
| TC-UPD-03 · Rollback protection | Firmware Update | 7.2 |
| TC-UPD-04 · Pre-installation integrity check | Firmware Update | 7.2 |
| TC-UPD-05 · Unsigned update rejection | Firmware Update | 7.2 |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | 4.2 |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | 4.2 |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | 4.2 |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | 4.2 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | 4.2 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | 4.2 |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | 4.2 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | 4.2 |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | 4.2 |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | 4.2 |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | 4.2 |
| TC-BIN-01 · Stack canary detection | Binary Hardening | 5.4 |
| TC-BIN-02 · NX/DEP bit verification | Binary Hardening | 5.4 |
| TC-BIN-03 · PIE/ASLR verification | Binary Hardening | 5.4 |
| TC-BIN-04 · RELRO configuration | Binary Hardening | 5.4 |
| TC-BIN-05 · Debug symbol stripping | Binary Hardening | 5.4 |
| TC-BIN-06 · Insecure RPATH/RUNPATH | Binary Hardening | 5.4 |
| TC-ATK-07 · Vulnerability disclosure policy presence | Attack Surface | 6.2 |
| TC-CVE-01 · OS and kernel CVE scan | Known Vulnerabilities | 6.1 |
| TC-CVE-02 · BusyBox CVE scan | Known Vulnerabilities | 6.1 |
| TC-CVE-03 · TLS library CVE check | Known Vulnerabilities | 6.1 |
| TC-CVE-04 · SBOM generation | Known Vulnerabilities | 5.2.4 |
| TC-CVE-05 · Known vulnerable binary hash match | Known Vulnerabilities | 6.1 |
| TC-CVE-06 · Firmware-wide critical CVE presence | Known Vulnerabilities | 6.1 |
| TC-CVE-07 · CVE regression from prior firmware version | Known Vulnerabilities | 6.1 |
| TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVE | Known Vulnerabilities | 6.1 |
| TC-CVE-09 · End-of-life component in the SBOM | Known Vulnerabilities | 6.1 |
FDA Premarket Cybersecurity (524B)2023 · 60 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | (b)(1) |
| TC-CRED-02 · Default credential database match | Credential Security | (b)(1) |
| TC-CRED-03 · Password hash strength assessment | Credential Security | (b)(1) |
| TC-CRED-04 · API key and token detection | Credential Security | (b)(1) |
| TC-CRED-05 · Embedded private key detection | Credential Security | (b)(1) |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | (b)(1) |
| TC-CRED-07 · Account with no password set | Credential Security | (b)(1) |
| TC-UPD-01 · Update signature verification presence | Firmware Update | (b)(1) |
| TC-UPD-02 · Update channel encryption | Firmware Update | (b)(1) |
| TC-UPD-03 · Rollback protection | Firmware Update | (b)(1) |
| TC-UPD-04 · Pre-installation integrity check | Firmware Update | (b)(1) |
| TC-UPD-05 · Unsigned update rejection | Firmware Update | (b)(1) |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | (b)(1) |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | (b)(1) |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | (b)(1) |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | (b)(1) |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | (b)(1) |
| TC-CRYPTO-06 · Certificate validation | Cryptography | (b)(1) |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | (b)(1) |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | (b)(1) |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | (b)(1) |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | (b)(1) |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | (b)(1) |
| TC-BIN-01 · Stack canary detection | Binary Hardening | (b)(2) |
| TC-BIN-02 · NX/DEP bit verification | Binary Hardening | (b)(2) |
| TC-BIN-03 · PIE/ASLR verification | Binary Hardening | (b)(2) |
| TC-BIN-04 · RELRO configuration | Binary Hardening | (b)(2) |
| TC-BIN-05 · Debug symbol stripping | Binary Hardening | (b)(2) |
| TC-BIN-06 · Insecure RPATH/RUNPATH | Binary Hardening | (b)(2) |
| TC-ATK-01 · Telnet service detection | Attack Surface | (b)(2) |
| TC-ATK-02 · FTP service detection | Attack Surface | (b)(2) |
| TC-ATK-03 · Debug tool presence | Attack Surface | (b)(2) |
| TC-ATK-04 · UART debug shell detection | Attack Surface | (b)(2) |
| TC-ATK-05 · Unnecessary network services | Attack Surface | (b)(2) |
| TC-ATK-06 · Web interface privilege check | Attack Surface | (b)(2) |
| TC-ATK-07 · Vulnerability disclosure policy presence | Attack Surface | (b)(2) |
| TC-CVE-01 · OS and kernel CVE scan | Known Vulnerabilities | (b)(2) |
| TC-CVE-02 · BusyBox CVE scan | Known Vulnerabilities | (b)(2) |
| TC-CVE-03 · TLS library CVE check | Known Vulnerabilities | (b)(2) |
| TC-CVE-04 · SBOM generation | Known Vulnerabilities | (b)(3) |
| TC-CVE-05 · Known vulnerable binary hash match | Known Vulnerabilities | (b)(2) |
| TC-CVE-06 · Firmware-wide critical CVE presence | Known Vulnerabilities | (b)(2) |
| TC-CVE-07 · CVE regression from prior firmware version | Known Vulnerabilities | (b)(2) |
| TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVE | Known Vulnerabilities | (b)(2) |
| TC-CVE-09 · End-of-life component in the SBOM | Known Vulnerabilities | (b)(2) |
| TC-RUN-01 · Memory-safety fault under adversarial input | Runtime Behaviour | (b)(2) |
| TC-RUN-02 · Network-reachable command execution surface | Runtime Behaviour | (b)(2) |
| TC-ATK-08 · Brute-force protection on network authentication | Attack Surface | (b)(2) |
| TC-ATK-09 · Pre-authentication information disclosure | Attack Surface | (b)(2) |
| TC-ATK-10 · Redundant root-privileged account | Attack Surface | (b)(2) |
| TC-ATK-11 · Security event logging present | Attack Surface | (b)(2) |
| TC-ATK-12 · Management interface served over cleartext HTTP | Attack Surface | (b)(2) |
| TC-CODE-01 · Command or code injection in shipped scripts | Code Security | (b)(2) |
| TC-CODE-02 · Untrusted input rendered by the device web interface | Code Security | (b)(2) |
| TC-CODE-03 · Untrusted input selects a file path | Code Security | (b)(2) |
| TC-CODE-04 · Untrusted data parsed by an interpreter or database | Code Security | (b)(2) |
| TC-BOOT-01 · Bootloader signature verification | Secure Boot | (b)(1) |
| TC-BOOT-02 · Boot measurement capability | Secure Boot | (b)(1) |
| TC-BOOT-03 · Recovery partition presence | Secure Boot | (b)(1) |
| TC-BOOT-04 · Runtime integrity verification | Secure Boot | (b)(1) |
TEC 31318 Code of Practice for Securing Consumer IoTTEC 31318:2025 Release 2.0 · 59 mapped checks
| Configured check | Category | Reference |
|---|---|---|
| TC-CRED-01 · Hardcoded credential detection | Credential Security | 3.1 |
| TC-CRED-02 · Default credential database match | Credential Security | 3.1 |
| TC-CRED-03 · Password hash strength assessment | Credential Security | 3.4 |
| TC-CRED-04 · API key and token detection | Credential Security | 3.4 |
| TC-CRED-05 · Embedded private key detection | Credential Security | 3.4 |
| TC-CRED-06 · Credentials stored in clear text on the device | Credential Security | 3.4 |
| TC-CRED-07 · Account with no password set | Credential Security | 3.1 |
| TC-UPD-01 · Update signature verification presence | Firmware Update | 3.3 |
| TC-UPD-02 · Update channel encryption | Firmware Update | 3.3 |
| TC-UPD-04 · Pre-installation integrity check | Firmware Update | 3.3 |
| TC-UPD-05 · Unsigned update rejection | Firmware Update | 3.3 |
| TC-CRYPTO-01 · MD5 usage in security context | Cryptography | 3.5 |
| TC-CRYPTO-02 · SHA-1 usage in security context | Cryptography | 3.5 |
| TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4) | Cryptography | 3.5 |
| TC-CRYPTO-04 · RSA key length validation | Cryptography | 3.5 |
| TC-CRYPTO-05 · TLS version enforcement | Cryptography | 3.5 |
| TC-CRYPTO-06 · Certificate validation | Cryptography | 3.5 |
| TC-CRYPTO-07 · Hardcoded IV/salt detection | Cryptography | 3.5 |
| TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3) | Cryptography | 3.5 |
| TC-CRYPTO-09 · Broken hash algorithm (MD4) | Cryptography | 3.5 |
| TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite) | Cryptography | 3.5 |
| TC-CRYPTO-11 · ECB block-cipher mode | Cryptography | 3.5 |
| TC-BIN-01 · Stack canary detection | Binary Hardening | 3.6 |
| TC-BIN-02 · NX/DEP bit verification | Binary Hardening | 3.6 |
| TC-BIN-03 · PIE/ASLR verification | Binary Hardening | 3.6 |
| TC-BIN-04 · RELRO configuration | Binary Hardening | 3.6 |
| TC-BIN-05 · Debug symbol stripping | Binary Hardening | 3.6 |
| TC-BIN-06 · Insecure RPATH/RUNPATH | Binary Hardening | 3.6 |
| TC-ATK-01 · Telnet service detection | Attack Surface | 3.6 |
| TC-ATK-02 · FTP service detection | Attack Surface | 3.6 |
| TC-ATK-03 · Debug tool presence | Attack Surface | 3.6 |
| TC-ATK-04 · UART debug shell detection | Attack Surface | 3.6 |
| TC-ATK-05 · Unnecessary network services | Attack Surface | 3.6 |
| TC-ATK-06 · Web interface privilege check | Attack Surface | 3.6 |
| TC-ATK-07 · Vulnerability disclosure policy presence | Attack Surface | 3.2 |
| TC-CVE-01 · OS and kernel CVE scan | Known Vulnerabilities | 3.3 |
| TC-CVE-02 · BusyBox CVE scan | Known Vulnerabilities | 3.3 |
| TC-CVE-03 · TLS library CVE check | Known Vulnerabilities | 3.3 |
| TC-CVE-04 · SBOM generation | Known Vulnerabilities | 3.3 |
| TC-CVE-05 · Known vulnerable binary hash match | Known Vulnerabilities | 3.3 |
| TC-CVE-06 · Firmware-wide critical CVE presence | Known Vulnerabilities | 3.3 |
| TC-CVE-07 · CVE regression from prior firmware version | Known Vulnerabilities | 3.3 |
| TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVE | Known Vulnerabilities | 3.3 |
| TC-CVE-09 · End-of-life component in the SBOM | Known Vulnerabilities | 3.3 |
| TC-RUN-01 · Memory-safety fault under adversarial input | Runtime Behaviour | 3.13 |
| TC-RUN-02 · Network-reachable command execution surface | Runtime Behaviour | 3.13 |
| TC-ATK-08 · Brute-force protection on network authentication | Attack Surface | 3.1 |
| TC-ATK-09 · Pre-authentication information disclosure | Attack Surface | 3.1, 3.6 |
| TC-ATK-10 · Redundant root-privileged account | Attack Surface | 3.6 |
| TC-ATK-11 · Security event logging present | Attack Surface | 3.10 |
| TC-ATK-12 · Management interface served over cleartext HTTP | Attack Surface | 3.5 |
| TC-CODE-01 · Command or code injection in shipped scripts | Code Security | 3.13 |
| TC-CODE-02 · Untrusted input rendered by the device web interface | Code Security | 3.13 |
| TC-CODE-03 · Untrusted input selects a file path | Code Security | 3.13 |
| TC-CODE-04 · Untrusted data parsed by an interpreter or database | Code Security | 3.13 |
| TC-BOOT-01 · Bootloader signature verification | Secure Boot | 3.7 |
| TC-BOOT-02 · Boot measurement capability | Secure Boot | 3.7 |
| TC-BOOT-03 · Recovery partition presence | Secure Boot | 3.9 |
| TC-BOOT-04 · Runtime integrity verification | Secure Boot | 3.7 |
Source mapping SHA-256: a13128efb566020e8eef43058129008ea1dde9ffbee947c81dc88b451ec791b7
This identifies the published source inventory, not a customer assessment or a certification record.
How FDIE supports assessment evidenceQualify your firmware
Evaluate a representative product family.
Start with an authorised image whose contents your engineering team understands. Keep a reproducible record of what was recovered, which checks ran and what remains outside the assessment.
Repeat qualification when packaging, architecture or a major analysis version changes. A shared CPU name alone is not enough to carry a result from one product to another.
Record the image assumptions
Capture its identity, container format, known CPU family, operating-system assumptions and selected analysis build.
Check extraction
Compare recovered files and binaries with what the engineering team expects. Record encrypted, damaged or unsupported regions.
Separate static and runtime results
Review each method independently. Successful extraction does not prove that a binary ran or that a system booted.
Use an independent reference
Keep a known component or test case to check the output. Investigate unexplained identification or coverage differences.
Record the remaining work
Assign manual, hardware or additional testing for unanswered questions, and keep those limitations with the release decision.