@@ -3666,7 +3666,119 @@ The risk are then calculated and their applicability defined using the matrixes
<th>UC / App.</th>
</tr>
<tr>
<td>T.Logs_Disclosure</td>
<td>A Local attacker or Rogue user tries to gain access to the TOE's Log File in order to gain sensitive information on the TOE's security status and functions as well as other C-ITS stations</td>
<td>Logs and Configuration </td>
<td>Integrity, Availability, Confidentiality</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-0, INT-0, CON-1</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.Configuration_Tampering</td>
<td>A Local attacker or Rogue user tries to modify the TOE's Certificate Policy configuration data and therefore compromise the integrity of the TOE's applications or communication security</td>
<td>Logs and Configuration </td>
<td>Integrity, Availability, Confidentiality</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-0, INT-0, CON-1</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.Stored_Certificates_Tampering</td>
<td>A Local attacker or Rogue user tries to modify stored CA Certificates Enrolment Credential (EC) Authorization Ticket (AT) TLM certificate content and therefore compromise the confidentiality or integrity of the TOE's communications</td>
<td>Certificates</td>
<td>Integrity, Availability</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-1, INT-0</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.Administrators_Impersonation</td>
<td>An attacker (Remote attacker Local attacker or Rogue user) may gain access to TOE information by impersonating an authorized user or via privilege escalation of the TOE and thus disclose or manipulate TOE assets</td>
<td>Keys <br> Certificates <br> Station registration data <br> CA Network addresses <br> Policies <br> Trust lists <br> PKI services <br> Misbehaviour detection</td>
<td>Integrity, Availability, Confidentiality</td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>AVA-0, INT-0, CON-0</td>
<td></td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
<td>NA</td>
<td>NA</td>
<td>NA</td>
<td>High</td>
<td>UC4</td>
</tr>
<tr>
<td>T.Software_Tampering</td>
<td>A Local or Remote attacker tries to modify the TOE's software and therefore compromise the integrity of the TOE's applications </td>