@@ -1938,7 +1938,7 @@ Assumptions can be updated to be less stringent as more use cases and mitigation
**[AS-LR]:** An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.
## C.4 Risk assessments of threats
## C.4 Threats and risk assessments of threats
### C.4.1 General
@@ -2029,25 +2029,265 @@ MI-LOGG: Logging
MI-SDRF: Secure data read from product
MI-SDTR: Secure data transfer to another product
**[TH-USDA]:** An attacker may read or modify security-relevant data without proper authorization while stored or in transmission.
### C.4.3 List of threats, risk assessments, and mitigations
**[TH-DATA]:** An attacker may read or modify data without proper authorization while being processed, stored, or transmitted by the product.
**[TH-FUNC]:** An attacker may use or modify functions of the product without proper authorization.
Attacker may use unknown exploitable vulnerabilities in the product implementation to get unauthorized access to product assets.
**[TH-TRCH]:** An attacker may access or intercept the establishment of a communication channel over a network with a trusted system without proper authorization, or masquerade as a trusted system during the establishment.
Requirements that mitigate this threat: AUTH, AVAI, LMII, LOGG
Mitigations for Likelihood:
* Medium to Low: DOST
* High to Low: DOST
Mitigations for Impact:
* Medium to Low: (NTFY or WDOG), LMEM, LOGG
* High to Low: NTFY, WDOG, FDRP, LMEM, FAIR, LOGG
#### C.4.3.7 TH-DDOS: Denial of service attack on other products via exploitation of vulnerabilities or unauthorized use of product functions
Attacker may exploit vulnerabilities in the product to attack other products.
Guidance: Traffic amplication attacks and other misuses of product functions are considered vulnerabilities and/or unauthorized use for the purpose of this threat.