1. What is the maximum number of attempts within a certain time interval? 2. What happens when a certain number of failed authentication attempts is reached? 5.2: Implement a means to manage reports of vulnerabilities 5.2-1: The manufacturer shall make a vulnerability disclosure policy publicly available. This policy shall include, at a minimum: • contact information for the reporting of issues; and • information on timelines for: M M M M Minimally, for each of the device's logininterfaces, the device shall employ a rate-limiting mechanism that has a limitation on the number of authentication attempts within a certain time interval, and locks/delays additional authentication attempts after a limited number of failed authentication attempts. Supporting evidence shall describe the following: 1. Contact information for the reporting of issues by listing down all various contact mechanisms available for the public to report vulnerabilities, and where information of each of the contact mechanisms are located. E.g. Contact numbers and/or email address are listed on developer's CLS Publication #2 | Page 25 of 49

Select target paragraph3