Thursday, September 12, 2024
The Embedded Kit unveils the new web interface for CVE Scan, its security vulnerability scanner
Lyon, September 18, 2024 – The Embedded Kit releases the latest version of CVE Scan, its tool for detecting and managing security vulnerabilities, at SIDO Lyon 2024. This version contains, in particular, a new interactive web interface designed to improve decision-making through visual management of the vulnerability lifecycle, detailed documentation, and report generation.
Optimizing the maintenance of embedded systems security
The CVE Scan tool, which already enabled SBOM generation and in-depth vulnerability (CVE) detection, now includes graphical interfaces for vulnerability analysis and interactive dashboards. This web interface provides equipment manufacturers with the information needed to proactively address the security risks of their embedded systems. By allowing users to visualize all their vulnerabilities and their criticality levels, it facilitates the prioritization of security measures. Users have access to detailed CVE information, including NVD database data for in-depth analysis, as well as existing patches to accelerate updates. They can also add manual annotations to document decisions and changes made to each vulnerability, thus maintaining a transparent log of actions taken. "With this new interface, our goal is to provide developers with a tool that not only enables vulnerability identification but also offers actionable insights for managing vulnerabilities throughout the product lifecycle," said Julien Bernet, Security Manager. "These dashboards were designed to simplify the complex task of maintaining the security of embedded systems."
Facilitating compliance with the European Cyber Resilience Act
Under the Cyber Resilience Act (CRA), equipment manufacturers will be required to manage and remediate security vulnerabilities in their products by 2026. This regulation mandates the systematic identification and documentation of vulnerabilities, as well as their rapid management and remediation through security updates. CVE Scan is positioned as a crucial tool to accelerate this process thanks to its intuitive web interface, dashboards, and report export and sharing capabilities. "The new CVE Scan interface is a direct response to the evolving regulatory landscape and the needs of our users," said Pierre Gal, Product Manager. "We are committed to providing a comprehensive solution that supports compliance and enhances the security of our customers' products."
About The Embedded Kit
The Embedded Kit, a Witekio brand, provides everything equipment manufacturers need to design, connect, test, and secure their embedded systems. Its four ready-to-use products (Welma Yocto Linux, Kamea IoT, Pluma Test, and CVE Scan) are specifically designed for OEMs to facilitate and accelerate product development while ensuring complete control over the source code. For more information, visit TheEmbeddedKit.io or meet the team at SIDO Lyon 2024 at booth 0422 .
- Additional resources: – Video presentation of the CVE Scan web interface – Free trial of CVE Scan – CVE Scan technical documentation