Attacks against systems and platforms

We characterize these attacks as those that a remote adversary can carry out to spy on or modify information without insider credentials or other privileged access.

Affected entity: Mobile user

Risk: Spying and credentials stealing from user devices

  • Vulnerability: Unverified malicious binary SMS SIM updates (SD: authentication)

  • Vulnerability: Insecure transfer of customer credentials (SD: access control)

Risk: Account access, compromise and denial of service

  • Vulnerability: Exposure of internal network to external adversaries (SD: access control)

Affected entity: DFS Provider

Risk: Account access, compromise, and denial of service

  • Vulnerability: Insufficient protection of internal systems against external adversaries (SD: access control

Last updated