Detailedlikelihood: Lowseverity: HighDraft
CAPEC-477Signature Spoofing by Mixing Signed and Unsigned Content
Abstraction
Detailed
Status
Draft
Likelihood
Low
Severity
High
Description
An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as though it were signed data.
Metadata: detailed CAPEC pattern, status draft, likelihood low, severity high. Underlying weaknesses: CWE-693, CWE-311, CWE-319. Related CAPEC pattern: [object Object].
Related weaknesses· 3
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
| Weakness | Missing Encryption of Sensitive Datacwe-311 | 100% | live |
| Weakness | Cleartext Transmission of Sensitive Informationcwe-319 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.