nrf Cloud and Memfault Vulnerabilty Monitoring

NCS: 3.4.0
Chip: nRF54L15

Hello,


in the past months, there has been quite a change regarding Security and Vulnerability Monitoring on the Nordic Semiconductors side. I got a few questions regarding this.

1) Is there still a public Website for each NCS Version where i can see the Vulnerabilites? I only found a Website where i can report a security vulnerabilty but none where they are all listed.

2) nRF Cloud offers the possibilty to upload an SBOM under Services/Security Services and Scan it for Vulnerabilites. I followed this guide: https://docs.nrfcloud.com/docs/platform/sbom to         create a merged SBOM for Zephyr RTOS and uploaded it.  nRF Cloud reported only 4 Vulnerabilites for our project. Looking at the SBOM i saw that there are only a few valid Identifiers which   are used by the nRF Cloud. The big ones like zephyr and mcuboot are all skipped because of no identifier match against CVE database. This is likely a side effect of Nordics downstream     repos resulting in invalid CPE Identifier. 
 Is the Security Services like this even a valid source? Could there still be severial Vulnerabilites like from zephyr missing? Is there a valid method to track the NCS 3.4.0 for Vulnerabilties?

Thank you for your help.

Best regards
Jonas

Parents Reply Children
No Data
Related