SERTIT, P.O. Box 14, N-1306 Bærum postterminal, NORWAY Phone: +47 67 86 40 00 Fax: +47 67 86 40 09 E-mail: post@sertit.no Internet: www.sertit.no Sertifiseringsmyndigheten for IT-sikkerhet Norwegian Certification Authority for IT Security SERTIT-043 CR Certification Report Issue 0.1 4 March 2013 ZTE Access System Series ZXA10 C300 V2.0.0T2, C300M V3.0T2, C350M V3.0T2 CERTIFICATION REPORT - SERTIT STANDARD REPORT TEMPLATE SD 009 VERSION 2.1 11.11.2011 ZTE Access System Series EAL 2 + ALC_FLR.2 Page 2 of 20 SERTIT-043 CR Issue 1.0 4 March 2013 ARRANGEMENT ON THE RECOGNITION OF COMMON CRITERIA CERTIFICATES IN THE FIELD OF INFORMATION TECHNOLOGY SECURITY SERTIT, the Norwegian Certification Authority for IT Security, is a member of the above Arrangement and as such this confirms that the Common Criteria certificate has been issued by or under the authority of a Party to this Arrangement and is the Party’s claim that the certificate has been issued in accordance with the terms of this Arrangement The judgements contained in the certificate and Certification Report are those of SERTIT which issued it and the Norwegian evaluation facility (EVIT) which carried out the evaluation. There is no implication of acceptance by other Members of the Agreement Group of liability in respect of those judgements or for loss sustained as a result of reliance placed upon those judgements by a third party. [*] * Mutual Recognition under the CC recognition arrangement applies to EAL 2 but not to ALC_FLR.2. ZTE Access System Series EAL 2 + ALC_FLR.2 SERTIT-043 CR Issue 1.0 4 March 2013 Page 3 of 20 Contents 1 Certification Statement 5 2 Abbreviations 6 3 References 10 4 Executive Summary 11 4.1 Introduction 11 4.2 Evaluated Product 11 4.3 TOE scope 11 4.4 Protection Profile Conformance 11 4.5 Assurance Level 11 4.6 Security Policy 11 4.7 Security Claims 12 4.8 Threats Countered 12 4.9 Threats Countered by the TOE’s environment 12 4.10 Threats and Attacks not Countered 12 4.11 Environmental Assumptions and Dependencies 12 4.12 IT Security Objectives 12 4.13 Non-IT Security Objectives 13 4.14 Security Functional Requirements 14 4.15 Security Function Policy 14 4.16 Evaluation Conduct 14 4.17 General Points 15 5 Evaluation Findings 16 5.1 Introduction 16 5.2 Delivery 17 5.3 Installation and Guidance Documentation 17 5.4 Misuse 17 5.5 Vulnerability Analysis 17 5.6 Developer’s Tests 17 5.7 Evaluators’ Tests 17 6 Evaluation Outcome 18 6.1 Certification Result 18 6.2 Recommendations 18 Annex A: Evaluated Configuration 19 TOE Identification 19 TOE Documentation 19 TOE Configuration 20 ZTE Access System Series EAL 2 + ALC_FLR.2 Page 4 of 20 SERTIT-043 CR Issue 1.0 4 March 2013 ZTE Access System Se ries EAL 2 + ALC_FLR.2 ........ ­ .0.0 " 0 • • • • • 0 '0. • • '0" . • • • • • • • • • 0 . . • • • • • • • • • 0 • • • • 0 • • • • • • ' 0 •• • • • • • • • • • • • _ _ • • • • • • • • • • ,_ ........... .. . .. .. 1 Certification Statement ZTE Corporation ZTE Access System Series is an Access System, which regulates the access between networks. like a provider IP network or the PSTN or subscribers. who wish to access these networks. ZTE Access Syste m Se ri es ve rsi on ZXA 10 C300 V2.0.0T2, C300 M V3.0T2, C350M V3.0T2 has been evaluated under the terms of the Norwegian Certification Scheme for IT Security and have met the Common Criteria Part 3 (ISO/IEC 15408) conformant requirements of Evaluation Assurance Level EAL 2 augmented with ALC_FLR.2 for the specified Common Criteria Part 2 (ISO/IEC 15408) conformant functionality in the specified environment when running on the platforms specified in Annex A. I -_...­ I ; Author IKvassnes, Kjarta n J",geA Certifier I ~ j ... Quality Assurance ,Arne H0ye Rage I Quality Assurance ~t