CWE-290
Authentication Bypass by Spoofing
Description
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94
CVEs mapped to this weakness (677)
page 19 of 34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-1547 | Med | 0.42 | 6.5 | 0.01 | Feb 20, 2024 | Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. | ||
| CVE-2023-50463 | Med | 0.42 | 6.5 | 0.01 | Dec 10, 2023 | The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP… | ||
| CVE-2023-30950 | Med | 0.42 | 6.5 | 0.00 | Aug 3, 2023 | The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint | ||
| CVE-2022-48469 | Med | 0.42 | 6.5 | 0.00 | Jun 16, 2023 | There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers. | ||
| CVE-2023-33140 | Med | 0.42 | 6.5 | 0.02 | Jun 14, 2023 | Microsoft OneNote Spoofing Vulnerability | ||
| CVE-2023-2807 | Med | 0.42 | 6.4 | 0.01 | Jun 13, 2023 | Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all… | ||
| CVE-2023-0816 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2023 | The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections. | ||
| CVE-2022-3820 | Med | 0.42 | 6.5 | 0.01 | Jan 26, 2023 | An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in… | ||
| CVE-2022-4746 | Hig | 0.42 | 7.5 | 0.01 | Jan 23, 2023 | The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin. | ||
| CVE-2022-31738 | Med | 0.42 | 6.5 | 0.01 | Dec 22, 2022 | When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. | ||
| CVE-2022-41798 | Med | 0.42 | 6.5 | 0.01 | Dec 5, 2022 | Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows:… | ||
| CVE-2022-38164 | Med | 0.42 | 6.5 | 0.00 | Nov 7, 2022 | A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only display certain part of the entire URL. | ||
| CVE-2022-35770 | Med | 0.42 | 6.5 | 0.02 | Oct 11, 2022 | Windows NTLM Spoofing Vulnerability | ||
| CVE-2022-1129 | Med | 0.42 | 6.5 | 0.01 | Jul 23, 2022 | Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | ||
| CVE-2021-43807 | Hig | 0.42 | 7.5 | 0.01 | Dec 14, 2021 | Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method via URL parameter. This allows attackers to turn HTTP GET requests into PUT requests or an HTTP… | ||
| CVE-2021-31209 | Med | 0.42 | 6.5 | 0.03 | May 11, 2021 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2021-23984 | Med | 0.42 | 6.5 | 0.01 | Mar 31, 2021 | A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing… | ||
| CVE-2019-25023 | Med | 0.42 | 6.5 | 0.01 | Feb 27, 2021 | An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipulated client-side) is used for the internal application logs, an attacker can inject wrong IP addresses into these logs. | ||
| CVE-2020-24375 | Med | 0.42 | 6.5 | 0.01 | Oct 19, 2020 | A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3. | ||
| CVE-2020-1329 | Med | 0.42 | 6.5 | 0.03 | Jun 9, 2020 | A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'. |
- risk 0.42cvss 6.5epss 0.01
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
- risk 0.42cvss 6.5epss 0.01
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP…
- risk 0.42cvss 6.5epss 0.00
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
- risk 0.42cvss 6.5epss 0.00
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers.
- risk 0.42cvss 6.5epss 0.02
Microsoft OneNote Spoofing Vulnerability
- risk 0.42cvss 6.4epss 0.01
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all…
- risk 0.42cvss 6.5epss 0.01
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in…
- risk 0.42cvss 7.5epss 0.01
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.
- risk 0.42cvss 6.5epss 0.01
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
- risk 0.42cvss 6.5epss 0.01
Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows:…
- risk 0.42cvss 6.5epss 0.00
A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only display certain part of the entire URL.
- risk 0.42cvss 6.5epss 0.02
Windows NTLM Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.01
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- risk 0.42cvss 7.5epss 0.01
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method via URL parameter. This allows attackers to turn HTTP GET requests into PUT requests or an HTTP…
- risk 0.42cvss 6.5epss 0.03
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.01
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipulated client-side) is used for the internal application logs, an attacker can inject wrong IP addresses into these logs.
- risk 0.42cvss 6.5epss 0.01
A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
- risk 0.42cvss 6.5epss 0.03
A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'.