November 2017
Intermediate to advanced
452 pages
11h 46m
English
As we did in the previous recipe, we will need to rate each of the possible threats using DREAD. Using the following table, we will choose one threat and find out its risk rating:
|
Threat risk rating: Attacker could gain admin access to the filesystem and attack the LAN |
|
|
Item |
Score |
|
Damage potential |
3 |
|
Reproducibility |
2 |
|
Exploitability |
2 |
|
Affected users |
3 |
|
Discoverability |
2 |
|
Risk rating score: High |
12 |
Most embedded device operating systems typically run as root or admin. This means any vulnerability that may be exploited via a device's firmware should give you the highest access needed. There is no need for privilege escalation. More regulated industries may defer but ...
Read now
Unlock full access