5.4.9 The testing laboratory shall assess that third-party libraries/components
used by the firmware are compliant with respective license requirements
(GNU General Public License, BSD license, MIT, Creative Commons,
Apache, etc.).
5.4.10 The testing laboratory shall assess that there are no exploitable third-party
libraries/components. In the event that vulnerabilities are deemed to be
highly exploitable, the developer is required to update the
libraries/components to a version without vulnerabilities, or to implement a
custom patch/fix to address the vulnerability. The testing laboratory shall
re-test the binary code following developer’s remediation procedures. The
remediated findings and its remediation steps must be included in the
report to CCC.
5.4.11 The testing laboratory shall ensure that the firmware and the companion
mobile application does not contain hard-coded critical security
parameters.
5.4.12 For each false positive, the testing laboratory must work with the developer
to provide sufficient justification on why the finding is a false positive.
Malware Scan
5.4.13 Developer shall ensure that the binary files submitted is free from known
malware.
5.4.14 The binary files shall be subjected to a commercial malware scanner that
exists as a cloud solution for malware analysis. Therefore, the developer
shall consent to allowing the binary files to be uploaded to a commercial
malware scanner for malware analysis.
5.4.15 In the event that firmware and/or the companion mobile application tests
positive for malware, the initial malware scan results shall be confirmed
using a different malware scanner. If both malware scanners confirm that
the binary file tests positive for malware, CCC reserves the right to take
appropriate actions against the developer.
Mobile Application Scan
5.4.16 Where a companion mobile app is available to facilitate the usage of the
DUT, the companion mobile app shall be subjected to binary analysis. The
testing laboratory shall prioritise their analysis of the companion mobile app
on the following areas:
•
•
•
Hardcoded credentials or critical security parameters;
Exposure of sensitive information, for example via insecure storage
or insecure communication channels;
Potential intrusion to privacy for example whether the app requests
for rights/permissions that it is deemed not to require such as to
user’s calendar or device’s camera; or where data is sent out
CLS Publication #2 | Page 12 of 49