Typical severity: High. Likelihood of attack: Low. An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
Ensure cryptographic elements have been sufficiently tested for weaknesses.