VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (748)

page 32 of 38
  • CVE-2021-27862MedSep 27, 2022
    risk 0.31cvss 4.7epss 0.01

    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).

  • CVE-2021-27861MedSep 27, 2022
    risk 0.31cvss 4.7epss 0.01

    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)

  • CVE-2021-27854MedSep 27, 2022
    risk 0.31cvss 4.7epss 0.01

    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.

  • CVE-2021-27853MedSep 27, 2022
    risk 0.31cvss 4.7epss 0.01

    Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

  • CVE-2021-40823MedSep 13, 2021
    risk 0.31cvss 5.9epss 0.01

    A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by…

  • CVE-2025-56689MedSep 3, 2025
    risk 0.30cvss 4.6epss 0.01

    One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP…

  • CVE-2023-36769MedNov 6, 2023
    risk 0.30cvss 4.6epss 0.00

    Microsoft OneNote Spoofing Vulnerability

  • CVE-2022-44636MedDec 13, 2022
    risk 0.30cvss 4.6epss 0.00

    The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models.

  • CVE-2021-26418MedMay 11, 2021
    risk 0.30cvss 4.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2026-65399MedSep 14, 2026
    risk 0.29cvss 4.4epss 0.00

    A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An archive may be able to bypass Gatekeeper.

  • CVE-2026-39309MedMay 20, 2026
    risk 0.29cvss 5.5epss 0.00

    Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading…

  • CVE-2025-13635MedDec 2, 2025
    risk 0.29cvss 4.4epss 0.00

    Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2025-13634MedDec 2, 2025
    risk 0.29cvss 4.4epss 0.00

    Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-27853MedJul 29, 2024
    risk 0.29cvss 4.4epss 0.00

    This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

  • CVE-2025-68624MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid…

  • CVE-2026-73742MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to cause inaccurate attribution information to…

  • CVE-2026-48016MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards it to…

  • CVE-2026-13984MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-13636MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted domain name. (Chromium security severity: Low)

  • CVE-2025-43503MedNov 4, 2025
    risk 0.28cvss 4.3epss 0.00

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Visiting a malicious website may lead to user interface…