VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 3 of 38
  • CVE-2025-36753CriDec 13, 2025
    risk 0.64cvss 9.8epss 0.00

    The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from within the device

  • CVE-2025-8853CriAug 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

  • CVE-2025-36594CriAug 4, 2025
    risk 0.64cvss 9.8epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing…

  • CVE-2025-43245CriJul 30, 2025
    risk 0.64cvss 9.8epss 0.01

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.

  • CVE-2023-41591CriMay 29, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-middle attack on communications between fake and real hosts.

  • CVE-2025-32966CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.04

    DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.

  • CVE-2024-55210CriApr 9, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.

  • CVE-2025-27671CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Impersonation OVE-20230524-0015.

  • CVE-2025-1298CriFeb 14, 2025
    risk 0.64cvss 9.8epss 0.00

    Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.

  • CVE-2022-3180CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.09

    The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.

  • CVE-2025-21415CriJan 29, 2025
    risk 0.64cvss 9.9epss 0.01

    Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-13061CriDec 31, 2024
    risk 0.64cvss 9.8epss 0.01

    The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens…

  • CVE-2024-46957CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.

  • CVE-2024-29006CriApr 4, 2024
    risk 0.64cvss 9.8epss 0.01

    By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are…

  • CVE-2023-51350CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.01

    A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.

  • CVE-2023-4178CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.

  • CVE-2022-48513CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-25827CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.

  • CVE-2023-2887CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2021-43310CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.