@@ -2544,271 +2544,246 @@ For each threat, a formula based on the risk factor levels is used to calculate
For each threat, both likelihood and impact must be Low before the risk is considered sufficiently mitigated. If the calculated levels are not already Low, then mitigations must be applied until they are both Low. The mitigation sets that will accomplish this are listed in each threat description.
The risk factors by type are:
* Likelihood: PHY NET COM INI
* Impact: NET HOS FUN
### B.4.3 List of threats, risk assessments, and mitigations
* Medium to Low: (KEVD or KEVA or KEVT or SCAN), KEVM, (SUVP or SUAP or SUOE or SUAO), VULH
* Medium to Low:
* REQ-KEV-01
* REQ-SU-01
* High to Low: KEVD, KEVA, (KEVT or SCAN), KEVM, (SUAP or SUAO), VULH
* High to Low:
* REQ-KEV-01
* REQ-SU-01
#### B.4.3.3 TH-PHYS: Access to data via acquisition of used product
#### B.4.3.3 TH-DSTP Compromise of data stored on product
Attacker may get unauthorized access to confidential data stored on the product through acquisition of a used product.
Attacker may get unauthorized access to confidential data stored on the product through acquisition of a used product or during transfer of user data and settings from one product to another.