Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-477 — Signature Spoofing by Mixing Signed and Unsigned Content
CAPEC-477

Signature Spoofing by Mixing Signed and Unsigned Content

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as though it were signed data.

Mitigation

Ensure the application is fully patched and does not allow the processing of unsigned data as if it is signed data.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.