VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 19 of 34
  • CVE-2024-1547MedFeb 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

  • CVE-2023-50463MedDec 10, 2023
    risk 0.42cvss 6.5epss 0.01

    The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP…

  • CVE-2023-30950MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.00

    The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint

  • CVE-2022-48469MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.00

    There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers. 

  • CVE-2023-33140MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft OneNote Spoofing Vulnerability

  • CVE-2023-2807MedJun 13, 2023
    risk 0.42cvss 6.4epss 0.01

    Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all…

  • CVE-2023-0816MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

  • CVE-2022-3820MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in…

  • CVE-2022-4746HigJan 23, 2023
    risk 0.42cvss 7.5epss 0.01

    The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.

  • CVE-2022-31738MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

  • CVE-2022-41798MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows:…

  • CVE-2022-38164MedNov 7, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only display certain part of the entire URL.

  • CVE-2022-35770MedOct 11, 2022
    risk 0.42cvss 6.5epss 0.02

    Windows NTLM Spoofing Vulnerability

  • CVE-2022-1129MedJul 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-43807HigDec 14, 2021
    risk 0.42cvss 7.5epss 0.01

    Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method via URL parameter. This allows attackers to turn HTTP GET requests into PUT requests or an HTTP…

  • CVE-2021-31209MedMay 11, 2021
    risk 0.42cvss 6.5epss 0.03

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2021-23984MedMar 31, 2021
    risk 0.42cvss 6.5epss 0.01

    A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing…

  • CVE-2019-25023MedFeb 27, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipulated client-side) is used for the internal application logs, an attacker can inject wrong IP addresses into these logs.

  • CVE-2020-24375MedOct 19, 2020
    risk 0.42cvss 6.5epss 0.01

    A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.

  • CVE-2020-1329MedJun 9, 2020
    risk 0.42cvss 6.5epss 0.03

    A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'.