@@ -1735,16 +1735,19 @@ Type: Affects likelihood and impact of all attacks.
***[ADM-L-0]** Foreseeable use includes skilled administration, fully resourced
***[ADM-L-1]** Foreseeable use includes unskilled and/or under-resourced administration
**[SYS]**Access to host system assets
**[SYS]**Impact of access to host system assets
Description: Measures the degree of access to the host system assets, such as memory, other devices, and system management functions. This is usually a property of the communications bus used to connect to the host system. E.g., a network interface connected by USB versions below 4.0 can only access system resources via the host USB stack software, but a network interface on a PCIe bus (including tunneled over USB 4.0) or a virtual network interface that has privileged access to the host system can write any part of host system memory.
Description: Measures the impact of the product's access to host system assets.
The communications bus used to connect to the host system usually controls the level of access. E.g., a network interface connected by USB versions below 4.0 can only access system resources via the host USB stack software, but a network interface on a PCIe bus (including tunneled over USB 4.0) or a virtual network interface that has privileged access to the host system can write any part of host system memory.
Rationale: Access to host systems assets increases the impact of attacks.
Type: Affects impact of all attacks.
***[SYS-L-0]** Limited access or access mediated by host software to host system resources
***[SYS-L-1]** Extensive access to host system resources