Impact
The vulnerability arises from improper verification of cryptographic signatures and a failure to detect unusual or exceptional conditions during signature validation in Estonian Information System Authority’s libraries and applications. Based on the description, it is inferred that an attacker who can supply a manipulated signature or document might cause the software to accept a forged signature, allowing creation or alteration of digitally signed documents that appear legitimate, thereby undermining the integrity and authenticity guarantees that the DigiDoc ecosystem is designed to provide.
Affected Systems
The weakness affects libdigidocpp on versions 4.1.0 up to but not including 4.2.1; DigiDoc4 on versions 4.7.0 up to 4.8.1; DigiDoc Android on versions 2.7.0 up to 2.7.1; DigiDoc iOS on versions 2.8.0 up to 2.8.0. The products are part of the Estonian Information System Authority’s DigiDoc suite.
Risk and Exploitability
The CVSS base score of 4.4 indicates a low severity impact, and there is no EPSS data nor KEV listing, suggesting that no widespread exploitation has been observed. Nevertheless, based on the description, it is inferred that the flaw can be exploited by an attacker who can present a forged document to a user running one of the affected applications, thereby causing the signature to be accepted as valid. The likely attack vector involves the attacker supplying a document or signature that the vulnerable component will process, which is typically possible in environments where users open documents from untrusted sources or the software automatically verifies incoming signatures.
OpenCVE Enrichment