Table 3.3.
OWASP evaluation of the identification by machine ID risk.
FactorValueJustification
Technical Impact  
Loss of confidentiality1The data sent through this data flow is not encrypted therefore it is not confidential
Loss of integrity1The integrity of the data is not affected by this risk
Loss of availability1The availability of either this communication or the CAM service is affected by this risk
Loss of accountability9The threat agent can listen passively to the network
Business Impact  
Financial damage1No financial damage will come directly to the maker of the system by exploiting the risk.
Reputation damage5Exploiting the risk can lead customers to be suspicious of using the system
Non-compliance4The system does not take into account privacy concerns like anonymity so it does not comply with GDPR, but it complies with technical specifications which also do not take into account privacy.
Privacy violation9The number of people affected can be measured in the millions

or Create an Account

Close Modal
Close Modal