Detailedlikelihood: Lowseverity: HighDraft
CAPEC-475Signature Spoofing by Improper Validation
Abstraction
Detailed
Status
Draft
Likelihood
Low
Severity
High
Description
An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key.
Metadata: detailed CAPEC pattern, status draft, likelihood low, severity high. Underlying weaknesses: CWE-347, CWE-327, CWE-295. Related CAPEC patterns: [object Object], [object Object].
Related weaknesses· 3
Related attack patterns· 2
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Verification of Cryptographic Signaturecwe-347 | 100% | live |
| Weakness | Use of a Broken or Risky Cryptographic Algorithmcwe-327 | 100% | live |
| Weakness | Improper Certificate Validationcwe-295 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.