VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 14 of 38
  • CVE-2020-22660HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2022-44713HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Microsoft Outlook for Mac Spoofing Vulnerability

  • CVE-2022-2324HigJul 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions

  • CVE-2021-40288HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in TP-Link AX10v1 before V1_211014, allows a remote unauthenticated attacker to disconnect an already connected wireless client via sending with a wireless adapter specific spoofed authentication frames

  • CVE-2021-41753HigSep 27, 2021
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in D-Link DIR-X1560, v1.04B04, and DIR-X6060, v1.11B04 allows a remote unauthenticated attacker to disconnect a wireless client via sending specific spoofed SAE authentication frames.

  • CVE-2021-34548HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

  • CVE-2021-28810HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.01

    If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later

  • CVE-2020-17516HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.02

    Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the…

  • CVE-2020-28856HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.02

    OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP…

  • CVE-2020-11015HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address may pass to create new UDID with same MAC address. Full…

  • CVE-2019-11189HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass by Spoofing in org.onosproject.acl (access control) and org.onosproject.mobility (host mobility) in ONOS v2.0 and earlier allows attackers to bypass network access control via data plane packet injection. To exploit the vulnerability, an attacker sends a…

  • CVE-2019-15022HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing.

  • CVE-2018-15588HigFeb 11, 2019
    risk 0.49cvss 7.5epss 0.02

    MailMate before 1.11.3 mishandles a suspicious HTML/MIME structure in a signed/encrypted email.

  • CVE-2017-11717HigJul 28, 2017
    risk 0.49cvss 7.5epss 0.01

    MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.

  • CVE-2017-6405HigMar 2, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Hostname-based security is open to DNS spoofing.

  • CVE-2026-89022HigSep 15, 2026
    risk 0.48cvss 7.4epss 0.00

    BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers…

  • CVE-2026-67558HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live…

  • CVE-2026-16404HigJul 21, 2026
    risk 0.48cvss 7.4epss 0.00

    Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

  • CVE-2025-68644HigDec 21, 2025
    risk 0.48cvss 7.4epss 0.00

    Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to all cloud instances.

  • CVE-2025-27616HigMar 10, 2025
    risk 0.48cvss 8.5epss 0.00

    Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook payload with a specific set of headers and body data, an attacker could transfer ownership of a repository and its…