VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 24 of 38
  • CVE-2024-0454MedJan 12, 2024
    risk 0.39cvss 6.0epss 0.00

    ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows Hello recognition would be bypass with cloning SID to cause broken account identity. Version which is lower than…

  • CVE-2022-34716MedAug 9, 2022
    risk 0.39cvss 5.9epss 0.02

    .NET Spoofing Vulnerability

  • CVE-2020-7327MedOct 15, 2020
    risk 0.39cvss 6.0epss 0.00

    Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state…

  • CVE-2020-7326MedOct 15, 2020
    risk 0.39cvss 6.0epss 0.00

    Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MAR failing open rather…

  • CVE-2013-5661MedNov 5, 2019
    risk 0.39cvss 5.9epss 0.03

    Cache Poisoning issue exists in DNS Response Rate Limiting.

  • CVE-2019-1318MedOct 10, 2019
    risk 0.39cvss 5.9epss 0.04

    A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.

  • CVE-2026-73449MedSep 14, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can…

  • CVE-2026-45056MedSep 11, 2026
    risk 0.38cvss —epss 0.00

    matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted…

  • CVE-2026-84766MedSep 3, 2026
    risk 0.38cvss 5.9epss 0.00

    Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.

  • CVE-2026-72815MedAug 14, 2026
    risk 0.38cvss —epss 0.00

    go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting…

  • CVE-2026-6181MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.

  • CVE-2026-47381MedJun 23, 2026
    risk 0.38cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise another workspace's integration through the testConnection endpoint by supplying its ID, because the integration was fetched in a bypass scope and the caller's…

  • CVE-2025-46345MedMay 1, 2025
    risk 0.38cvss —epss 0.00

    Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper…

  • CVE-2024-20384MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic…

  • CVE-2024-20299MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have…

  • CVE-2024-20297MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have…

  • CVE-2024-39341MedSep 23, 2024
    risk 0.38cvss 5.9epss 0.00

    Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. WebAPI.cfg.xml) after the installation process. This file can be accessed without authentication on…

  • CVE-2024-20363MedMay 22, 2024
    risk 0.38cvss 5.8epss 0.00

    Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet…

  • CVE-2023-20246MedNov 1, 2023
    risk 0.38cvss 5.8epss 0.01

    Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access…

  • CVE-2023-20245MedNov 1, 2023
    risk 0.38cvss 5.8epss 0.00

    Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that…