Typical severity: High. Likelihood of attack: Low. An attacker provides a counterfeit component during the procurement process of a lower-tier component supplier to a sub-system developer or integrator, which is then built into the system being upgraded or repaired by the victim, allowing the attacker to cause disruption or additional compromise.
There are various methods to detect if the component is a counterfeit. See section II of [REF-703] for many techniques.