Detailedlikelihood: Mediumseverity: HighDraft
CAPEC-474Signature Spoofing by Key Theft
Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
High
Description
An attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Underlying weakness: CWE-522. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insufficiently Protected Credentialscwe-522 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Private Keyst1552.004 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.