Compliance Node Overview
MITRE CAPEC-477 (Signature Spoofing by Mixing Signed and Unsigned Content) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as though it were signed data. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-693, CWE-311, CWE-319.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/477.html
SHA-256 integrity: 07dd9da8c758caf7e326dfe033d5e6b0773412f8e05d92247201fde5354dec48
Primary Citations — 9 traced to source
- MITRE CAPEC-477: Signature Spoofing by Mixing Signed and Unsigned Content (https://capec.mitre.org/data/definitions/477.html)
- CWE-693: underlying weakness (http://cwe.mitre.org/data/definitions/693.html)
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.