VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 21 of 38
  • CVE-2024-9391MedOct 1, 2024
    risk 0.42cvss 6.5epss 0.00

    A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of…

  • CVE-2023-30464HigSep 18, 2024
    risk 0.42cvss 7.5epss 0.00

    CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.

  • CVE-2023-28452HigSep 18, 2024
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the…

  • CVE-2024-7745MedAug 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

  • CVE-2024-42364MedAug 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS rebinding. In this…

  • CVE-2024-39337MedJun 24, 2024
    risk 0.42cvss 6.5epss 0.00

    Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.

  • CVE-2024-36588MedJun 13, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.

  • CVE-2023-44447MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    TP-Link TL-WR902AC loginFs Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR902AC routers. Authentication is not required to exploit this…

  • CVE-2024-31008MedApr 3, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

  • CVE-2024-1547MedFeb 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

  • CVE-2023-50463MedDec 10, 2023
    risk 0.42cvss 6.5epss 0.01

    The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP…

  • CVE-2023-30950MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.00

    The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint

  • CVE-2022-48469MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.00

    There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers. 

  • CVE-2023-33140MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft OneNote Spoofing Vulnerability

  • CVE-2023-2807MedJun 13, 2023
    risk 0.42cvss 6.4epss 0.01

    Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all…

  • CVE-2023-0816MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

  • CVE-2022-3820MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in…

  • CVE-2022-4746HigJan 23, 2023
    risk 0.42cvss 7.5epss 0.01

    The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.

  • CVE-2022-31738MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

  • CVE-2022-41798MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows:…