Skip to main content

SQ20120

Detected digital signatures that use Elliptic Curve Cryptography parameters that could be easily spoofed.

priorityCI/CD statusseverityeffortRL levelRL assessment
passhighmediumNonetampering: warning
Reason: integrity enforcement errors

About the issueโ€‹

Digital signatures are applied to applications, packages and documents as a cryptographically secured authenticity record. Signatures verify the origin and the integrity of the object they apply to. The integrity validation relies on the cryptographic strength of the encryption and the hash verification algorithm. When Elliptic Curve Cryptography (ECC) is used, its parameters should be secured to prevent digital signature spoofing. Weak selection of parameters could allow a third-party to misrepresent its identity by matching the one in the signing certificate.

How to resolve the issueโ€‹

  • Have the signing certificate re-issued.
  • For more technical information, refer to CVE-2020-0601.