醫(yī)療器械網(wǎng)絡(luò)安全漏洞自評報告.doc(43頁)
目錄
醫(yī)療器械網(wǎng)絡(luò)安全漏洞自評報告1
1.目的3
2.引用文件3
3. CVSS 漏洞等級3
4.漏洞掃描報告12
5.漏洞總數(shù)和剩余漏洞數(shù)12
6.競爭條件(CWE-362: Race Condition)18
7.輸入驗證(CWE-20: Improper Input Validation)19
8.緩沖區(qū)錯誤(CWE-119: Buffer Errors)20
9.格式化字符串(CWE-134: Format String Vulnerability)22
10.跨站腳本(CWE-79: Cross-site Scripting)23
12.后置鏈接(CWE-59: Link Following)25
13.注入(CWE-74: Injection)26
14.代碼注入(CWE-94: Code Injection)27
15.命令注入(CWE-77: Command Injection)29
16. SQL 注入(CWE-89: SQL Injection)30
17.操作系統(tǒng)命令注入(CWE-78: OS Command Injection)31
18.安全特征問題(CWE-254: Security Features)32
19.授權(quán)問題(CWE-287: Improper Authentication)33
20.信任管理(CWE-255: Credentials Management)34
21.加密問題(CWE-310: Cryptographic Issues)35
21.1描述35
22.未充分驗證數(shù)據(jù)可靠性(CWE-345: Insufficient Verification of Data Authenticity)36
23.跨站請求偽造(CWE-352: Cross-Site Request Forgery)37
24.權(quán)限許可和訪問控制(CWE-264: Permissions, Privileges, and Access Controls)38
25.訪問控制錯誤(CWE-284: Improper Access Control)39
26.資料不足40
重要漏洞實例42
漏洞簡述42
結(jié)論43
6.剩余漏洞的維護方案43
網(wǎng)絡(luò)設(shè)備安全建議:43
總結(jié)43
下載該資料的還下載
相關(guān)資料
相關(guān)評論
您的評論: 推薦
發(fā)表評論 可以輸入500字