1. What is the maximum number of
attempts within a certain time
interval?
2. What happens when a certain
number of failed authentication
attempts is reached?
5.2:
Implement a
means to
manage
reports of
vulnerabilities
5.2-1:
The manufacturer shall
make
a
vulnerability
disclosure policy publicly
available. This policy shall
include, at a minimum:
• contact information for the
reporting of issues; and
• information on timelines
for:
M
M
M
M
Minimally, for each of the device's logininterfaces, the device shall employ a
rate-limiting mechanism that has a
limitation
on
the
number
of
authentication attempts within a certain
time interval, and locks/delays additional
authentication attempts after a limited
number
of
failed
authentication
attempts.
Supporting evidence shall describe the
following:
1. Contact information for the
reporting of issues by listing down
all various contact mechanisms
available for the public to report
vulnerabilities,
and
where
information of each of the contact
mechanisms are located. E.g.
Contact numbers and/or email
address are listed on developer's
CLS Publication #2 | Page 25 of 49