Authenticate firmware before installation
An attacker substitutes the firmware package on the delivery path. Whether the attack succeeds depends on the checks performed by the update client.
The device shall verify the firmware package before installation.
Submit a package with an invalid signature. Check that the update is rejected before any firmware is written.