Table 4.
Comparison of threats to Corona-Warn [89] and MyTrace [97] using the Common Weakness Enumerators (CWEs) listed in Table 3 (with a severity rating: H=high, M=medium, and L=low) against the common threat assessment model.
| Threat | Corona-Warn Matched CWEs | MyTrace Matched CWEs |
| Fake alert injection | N/Aa | CWE-327-H |
| False report | CWE-295-H, CWE-327-L | N/A |
| Proximity beacons altered | N/A | CWE-89-H |
| User can deny or retract infection report or contact details | CWE-295-H | N/A |
| Personal information disclosed | CWE-327-L, CWE295-H | CWE-89-H, CWE-276-H |
| User deanonymized and tracked | CWE327-L, CWE295-H | CWE-89-H, CWE-276-H, CWE-532-H |
| Energy resource drain attack | N/A | CWE-276-H |
| System resource contention | N/A | CWE276-H |
aN/A: not applicable.