CAPEC Definitions

    CAPEC Definitions / CAPEC-475

    CAPEC-475: Signature Spoofing by Improper Validation

    An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key.

    Severity:High
    Possibility:Low

    Extended Description

    Signature verification algorithms are generally used to determine whether a certificate or piece of code (e.g. executable, binary, etc.) possesses a valid signature and can be trusted. If the leveraged algorithm confirms that a valid signature exists, it establishes a foundation of trust that is further conveyed to the end-user when interacting with a website or application. However, if the signature verification algorithm improperly validates the signature, either by not validating the signature at all or by failing to fully validate the signature, it could result in an adversary generating a spoofed signature and being classified as a legitimate entity. Successfully exploiting such a weakness could further allow the adversary to reroute users to malicious sites, steals files, activates microphones, records keystrokes and passwords, wipes disks, installs malware, and more.

    Mitigations

    Use programs and products that contain cryptographic elements that have been thoroughly tested for flaws in the signature verification routines.

    Relationships with other CAPECs

    CAPEC-473: Signature Spoof

    CAPEC-542: Targeted Malware

    Prerequisites

    Recipient is using a weak cryptographic signature verification algorithm or a weak implementation of a cryptographic signature verification algorithm, or the configuration of the recipient's application accepts the use of keys generated using cryptographically weak signature verification algorithms.

    Related Weaknesses

    CWE-347: Improper Verification of Cryptographic Signature

    CWE-327: Use of a Broken or Risky Cryptographic Algorithm

    CWE-295: Improper Certificate Validation