VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 23 of 38
  • CVE-2024-4846MedJun 25, 2024
    risk 0.41cvss 6.3epss 0.00

    Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.

  • CVE-2024-23558MedApr 15, 2024
    risk 0.41cvss 6.3epss 0.00

    HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2023-6044MedJan 19, 2024
    risk 0.41cvss 6.3epss 0.00

    A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitrary code with elevated privileges.

  • CVE-2024-51406MedNov 1, 2024
    risk 0.40cvss 6.2epss 0.00

    Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.

  • CVE-2024-8386MedSep 3, 2024
    risk 0.40cvss 6.1epss 0.00

    If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

  • CVE-2024-31784MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.

  • CVE-2024-30190MedApr 9, 2024
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA…

  • CVE-2024-30189MedApr 9, 2024
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0) (All versions), SCALANCE…

  • CVE-2023-24935MedApr 11, 2023
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2020-13529MedMay 10, 2021
    risk 0.40cvss 6.1epss 0.01

    An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to…

  • CVE-2021-21310MedFeb 11, 2021
    risk 0.40cvss 6.1epss 0.02

    NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction with the Email provider are impacted.…

  • CVE-2018-8278MedJul 11, 2018
    risk 0.40cvss 6.1epss 0.07

    A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.

  • CVE-2026-90447HigSep 11, 2026
    risk 0.39cvss —epss 0.00

    A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service…

  • CVE-2026-75037HigAug 25, 2026
    risk 0.39cvss 7.0epss 0.00

    Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.

  • CVE-2026-0292MedAug 13, 2026
    risk 0.39cvss 6.0epss 0.00

    An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access…

  • CVE-2026-50141HigJun 18, 2026
    risk 0.39cvss —epss 0.00

    Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` value into outgoing gRPC…

  • CVE-2026-41299HigApr 21, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadata from WebSocket handshake rather than verified authorization state. Authenticated operator clients…

  • CVE-2024-32977HigMay 14, 2024
    risk 0.39cvss 7.1epss 0.01

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within…

  • CVE-2023-51747HigFeb 27, 2024
    risk 0.39cvss 7.1epss 0.01

    Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop,…

  • CVE-2023-7169MedFeb 8, 2024
    risk 0.39cvss 6.0epss 0.00

    Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0