Sign in
Ningxia Region | Beijing Region
Categories
Your Saved List Become a Channel Partner Sell in Amazon Web Services Marketplace Global Expansion Hub Amazon Web Services Home Help
Amazon Web Services Marketplace China: Embedded Firmware Security Analysis
    Listing Thumbnail

    Embedded Firmware Security Analysis

     
    Embedded Firmware Security Analysis The embedded firmware security analysis platform is independently developed by Guangdong Weichen Information Technology Co., Ltd. to provide full-life cycle firmware security for key industries such as the Internet of Things, automotive electronics, industrial control systems, and communication equipment. The platform incorporates capabilities such as a high-performance scan engine, AI large model intelligent analysis, and transparent management of the SBOM supply chain to help enterprises complete in-depth firmware security assessments in a short period of time.

    Overview

    Vulnerability scan engine The platform is equipped with a self-developed high-performance scanning engine. It supports the three authoritative vulnerability databases: CVE International Vulnerability Database, CNNVD National Vulnerability Database, and CAVD Vehicle Network Vulnerability Database, covering all vulnerability records from 2000 to now. The scanning speed reached the minute level (measured about 2 minutes/firmware), and the efficiency was outstanding. It supports more than 40 firmware formats (including QNX6, UBI/UBIFS, MCU .hex/.s19, Android APK, etc.) and more than 9 CPU architectures (x86/x64/ARM7/9/11/Arm64/MIPS/PowerPC/SuperH). The vulnerability result output includes CVE/CNNVD/CAVD numbers, CVSS scores, risk levels, vulnerability localization, fix suggestions, and POC evidence chains.

    SBOM supply chain analysis The platform automatically generates a software bill of materials (SBOM) that meets international standards, and also supports CycloneDX 1.5 and SPDX 2.3 dual-format output, which can simultaneously meet the two major standards. The component identification accuracy rate exceeds 95%, can recognize 826 SPDX standard licenses, automatically evaluate high-risk license conflicts such as GPL/LGPL/MPL, and help enterprises avoid open source compliance legal risks.

    AI intelligent analysis It integrates a large language model (supports multiple mainstream AI service standard interface access) and RAG core special knowledge base to achieve real-time response at the millisecond level through SSE streaming. AI analysis covers scenarios such as vulnerability interpretation, security baseline assessment, SBOM analysis, and sensitive feature interpretation, improving report writing efficiency by more than 80%.

    Binary safety baseline testing The binary files in the firmware are tested one by one for 9 security features: PIE (address space randomization), NX (data execution protection), RELLO (relocation read-only protection), Stack Canary (stack overflow protection), FORTIFY (compile-time security hardening), CFI (control flow integrity), SafeStack (safe stack), RPATH/RUNPATH (dynamic link path safety), and stripped (symbol table stripping) to comprehensively evaluate the level of firmware binary security hardening.

    Sensitive information leak detection Automatically detects potentially sensitive information leaks in firmware, including hardcoded usernames/passwords, SSL/TLS private key certificates, API keys, access tokens, full IP/URLs, private data, backup files (.bak/.old), and version control legacy files (.git/.svn).

    Smart report export It supports one-click export of professional safety assessment reports in various formats such as PDF, XLSX, DOCX, CycloneDX JSON, and SPDX JSON. PDF rendering supports Chinese layout, and supports custom report templates and corporate brand logos.

    Applicable industries Automotive electronics: ECU/domain control firmware safety inspection, SBOM management, PSIRT process integration, in line with GB 44495 and SAE ISO 21434 standards Internet of Things (IoT): Firmware security assessment for smart homes, smart terminals, and wearable devices, in line with EN 18031 and CRA standards Industrial control system: industrial control equipment entry inspection, in-service inspection, supply chain audit Communication equipment: -Firmware security testing of network devices such as routers, switches, base stations, etc. Third-party testing agency: firmware acceptance, type inspection, compliance certification

    Compliance support The platform meets many domestic and international security compliance standards: CycloneDX 1.5, SPDX 2.3 (ISO/IEC 5962), Cyber Resilience Act (CRA), EN 18031 (IoT Security Standard), GB 44495 (Intelligent Connected Vehicle Cybersecurity), SAE ISO 21434 (Vehicle Information Security Engineering), and ISO 27001.

    Highlights

    • Highlight 1: High-speed scanning, complete in-depth firmware security assessment in minutes Equipped with a self-developed Go high-performance concurrent scanning engine, it can complete a deep security scan of a single complete firmware in about 2 minutes, covering vulnerability detection, binary security baselines, sensitive information leakage, and SBOM supply chain analysis, shortening the security inspection cycle of a single firmware, and helping enterprises speed up the pace of product safety verification and launch.
    • Highlight 2: Deeply empowered by AI, security insights at your fingertips The platform incorporates a large AI model (supports multiple mainstream AI service standard interfaces) and RAG core specialized knowledge base to achieve millisecond intelligent analysis through SSE streaming. It supports natural language interpretation of vulnerabilities, security baselines, SBOM components, and YARA features and generates repair suggestions. The efficiency of writing security reports can be increased by more than 80%, making it easier for non-security personnel to understand risks and respond quickly.
    • Highlight 3: Dual vulnerability library + dual format SBOM to fully meet domestic and foreign compliance requirements It is the only domestic firmware security analysis platform that supports both the CVE International Vulnerability Library and the CNNVD National Vulnerability Database, and supports the CAVD Vehicle Network Vulnerability Library (Enterprise Edition). SBOM simultaneously outputs CycloneDX 1.5 and SPDX 2.3, and recognizes 826 SPDX licenses, fully covering domestic and international compliance standards such as the Cyber Resilience Act (CRA), EN 18031, GB 44495, SAE ISO 21434, etc., and satisfies multiple regulatory requirements at the same time.

    Details

    Delivery method

    Pricing

    Embedded Firmware Security Analysis

     
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional Amazon Web Services infrastructure costs may apply. Use the Amazon Web Services Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (2)

     
    Dimension
    Description
    Cost/month
    VeCenTekScan Professional - Firmware Safety Analysis Platform (monthly/yearly subscription)
    VeCenTekScan Professional Edition for enterprise-grade firmware security assessments and compliance checks. Core capabilities include: high-performance scan engine, CVE+CNNVD dual-vulnerability library coverage (2000-2026), 40+ firmware formats and 9+ CPU architecture support, CycloneDX 1.5+SPDX 2.3 dual-format SBOM generation (826 license recognition), 9 binary security baseline detection, sensitive information leak detection, AI large model intelligent analysis (SSE streaming response), multi-format report export (PDF/XLSX/DOCX). It supports firmware security testing in IoT, industrial control, communication equipment and other industries, and meets compliance requirements such as the Cyber Resilience Act and EN 18031.
    CN¥17,800.00
    VeCentekScan Enterprise Edition - Firmware security analysis platform with CAVD automotive vulnerability library (monthly/annual subscription)
    VeCenTekScan Enterprise Edition includes the CAVD Vehicle Network Vulnerability Library in addition to all the capabilities of the Professional Edition, and is specially designed for the automotive electronics industry. New capabilities: CAVD automotive vulnerability library (covering ECU/domain control firmware specific vulnerabilities), complete PSIRT process support, compliance with GB 44495 intelligent connected vehicle network security standards and SAE ISO 21434 automotive information security engineering standards. Applicable scenarios: automotive OEM/Tier 1 supplier ECU firmware safety compliance, pre-production safety inspection, SBOM supply chain governance and license compliance audit. The enterprise version enjoys exclusive technical support engineers, 7x24 hour response (1 hour response for P1 failure), and priority function iteration support.
    CN¥35,800.00

    Vendor refund policy

    All sales are final. Refunds are considered within 7 days of contract start only if a critical defect is confirmed by our support team and cannot be resolved. Used scan credits, subscription time, and frequent traffic are non-refundable. To request a refund, email support@vecentek.com  with your Amazon Web Services Account ID, Order ID, purchase date, and issue description. We respond within 3 business days. Contact: support@vecentek.com  | <www.vecentek.com >

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. Amazon Web Services Marketplace China does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software products directly to customers over the internet. You can access these products through a subscription model. You will pay recurring monthly usage fees for your subscription.

    Support

    Vendor support

    Support email: support@vecentek.com 

    Business and pre-sales inquiries: zhuyf@vecentek.com 

    Official website: <www.vecentek.com >

    Tel: +86-028-64148458

    Amazon Web Services infrastructure support

    Amazon Web Services Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Customer reviews

    Ratings and reviews

     
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product .