CAPEC-477: Signature Spoofing by Mixing Signed and Unsigned Content
An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as though it were signed data.
Severity
High
Likelihood
Low
3
/ 100
low-risk
Active Threat
2/50 · Minimal
Exploit Availability
1/50 · Minimal