VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 11 of 34
  • CVE-2026-33661HigMar 26, 2026
    risk 0.49cvss 8.6epss 0.01

    Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host.…

  • CVE-2026-24372HigMar 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10.

  • CVE-2026-32666HigMar 21, 2026
    risk 0.49cvss 7.5epss 0.00

    WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or…

  • CVE-2025-69401HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2.

  • CVE-2025-59802HigDec 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF…

  • CVE-2025-14327HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.

  • CVE-2025-12430HigNov 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-27916HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.

  • CVE-2025-6188HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.00

    On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of…

  • CVE-2025-3875HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.00

    Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats [email protected] as the actual address. This…

  • CVE-2025-46573HigMay 6, 2025
    risk 0.49cvss epss 0.00

    passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by tampering with a valid SAML response.…

  • CVE-2024-55925HigJan 23, 2025
    risk 0.49cvss 7.5epss 0.00

    In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This…

  • CVE-2024-8935HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.00

    CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is…

  • CVE-2024-8901HigOct 22, 2024
    risk 0.49cvss 7.5epss 0.00

    The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio/tree/master provides an OIDC authentication mechanism that was integrated into the open source Kubeflow project. The adapter uses JWT for authentication, but…

  • CVE-2024-10125HigOct 22, 2024
    risk 0.49cvss 7.5epss 0.00

    The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#validatetokensignature contains Middleware that can be used in conjunction with the Application Load Balancer (ALB) OpenId Connect integration and can be used in…

  • CVE-2024-49193HigOct 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is…

  • CVE-2024-39350HigJun 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may…

  • CVE-2023-4566HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44117HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-35622HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows DNS Spoofing Vulnerability