@@ -3354,7 +3354,7 @@ The risk are then calculated and their applicability defined using the matrixes
<tr>
<td>T_MITM</td>
<td>T.MITM</td>
<td>A Remote attacker may exploit interactions between the TOE and the ITS-S to expose or tamper sensitive TOE or user data</td>
<td>Keys <br> Certificates <br> Station registration data <br> Trust lists <br> Misbehaviour detection </td>
<td>Integrity, Availability, Confidentiality</td>
@@ -3426,9 +3426,187 @@ The risk are then calculated and their applicability defined using the matrixes
<th>UC / App.</th>
</tr>
<tr>
<td>T.DOS</td>
<td>A Remote attacker disables communication between the TOE and the ITS-S station</td>
<td>PKI services </td>
<td>Integrity, Availability</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-1, INT-0</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.ITS-S_Impersonation</td>
<td>A Remote attacker (Rogue ITS-S) sends fake requests in order to get valid EC and AT with forged attributes or fake MR in order to have targeted ITS-S to be considered misbehaving by the TAE</td>
<td>A Remote attacker intercepts and responds to an ITS-S requesting for trust list (CRL CTL ECTL) updates by sending an old version</td>
<td>Trust lists </td>
<td>Integrity, Availability</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-1, INT-0</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.GlobalMisbehaviourReportingTampering</td>
<td>A Remote attacker may exploit interactions between the MA and the EA or AA in order to modify global misbehaving detection information in order to force wrong reaction either on correct ITS-S station or misbehaving stations</td>
<td>A Remote attacker may exploit interactions between the EA and AA in order to modify Authorization calidation requests or responses to allow or deny inappropriate AT generation </td>
<td>Certificates <br> PKI services </td>
<td>Integrity, Availability</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-1, INT-0</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.RegistrationTampering</td>
<td>A Remote attacker may exploit interactions between the manufacturer and the EA in order to modify or deny an ITS-S registration </td>
<td>Station registration Data </td>
<td>Integrity, Availability, Confidentiality</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-0, INT-0, CON-0</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.PrivateKeys</td>
<td>A Local attacker or Rogue user disclose or tamper to the TOE secrets i.e. Data encryption key or CA private keys </td>
<td>Keys </td>
<td>Integrity, Availability, Confidentiality</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-0, INT-0, CON-0</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.Logs_Tampering</td>
<td>A Local attacker or Rogue user tries to modify the TOE's Log File in order to hide its activities </td>