Detailedlikelihood: Lowseverity: HighDraft
CAPEC-485Signature Spoofing by Key Recreation
Abstraction
Detailed
Status
Draft
Likelihood
Low
Severity
High
Description
An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Insufficiently Random Valuescwe-330 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Private Keyst1552.004 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.