VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 13 of 38
  • CVE-2025-14327HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.

  • CVE-2025-12430HigNov 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-27916HigNov 6, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.

  • CVE-2025-6188HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.00

    On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of…

  • CVE-2025-3875HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.00

    Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats [email protected] as the actual address. This…

  • CVE-2025-46573HigMay 6, 2025
    risk 0.49cvss —epss 0.00

    passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by tampering with a valid SAML response.…

  • CVE-2024-55925HigJan 23, 2025
    risk 0.49cvss 7.5epss 0.00

    In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This…

  • CVE-2024-8935HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.01

    CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is…

  • CVE-2024-8901HigOct 22, 2024
    risk 0.49cvss 7.5epss 0.00

    The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio/tree/master provides an OIDC authentication mechanism that was integrated into the open source Kubeflow project. The adapter uses JWT for authentication, but…

  • CVE-2024-10125HigOct 22, 2024
    risk 0.49cvss 7.5epss 0.00

    The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#validatetokensignature contains Middleware that can be used in conjunction with the Application Load Balancer (ALB) OpenId Connect integration and can be used in…

  • CVE-2024-49193HigOct 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is…

  • CVE-2024-39350HigJun 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may…

  • CVE-2023-4566HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44117HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-35622HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows DNS Spoofing Vulnerability

  • CVE-2023-25743HigJun 2, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

  • CVE-2022-47522HigApr 15, 2023
    risk 0.49cvss 7.5epss 0.01

    The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point…

  • CVE-2022-4550HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.01

    The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing

  • CVE-2022-47648HigFeb 8, 2023
    risk 0.49cvss 7.6epss 0.00

    An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid…

  • CVE-2022-4303HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.01

    The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms.