Appendix EThreat Scenario Weakness and Vulnerabilities Risk Ratings
E.1 Risk Assessment for Threat Scenario TS1
The OWASP risk rating methodology was applied to assess the risk severity of CVEs and CWEs specifically targeted by threat agents in threat scenario TS1. This scenario involves malicious actors exploiting a DeFi dApp’s mobile user interface by targeting vulnerabilities related to authentication, data exposure, and input validation. The risk evaluation focused on how these known weaknesses, such as CWE-287 (improper authentication) and CWE-359 (exposure of private information), could be exploited by skilled attackers and financially motivated cybercriminals.
The likelihood of exploitation was determined by assessing the threat landscape, attacker capabilities, and the ease of discovering and exploiting the vulnerabilities. In parallel, the impact was evaluated from both a technical and business perspective, considering consequences such as unauthorized access, financial loss, and regulatory exposure. This structured approach enables precise prioritization of vulnerabilities within TS1, helping guide mitigation efforts before production deployment.
E.2 Risk Severity Evaluation of CWEs and CVEs in Threat Scenario TS1 Using the OWASP Risk Rating Methodology
The OWASP risk rating methodology assesses risk by combining the likelihood of a threat successfully exploiting a weakness with the potential impact of that exploitation. Likelihood is evaluated based on ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access