VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (747)

page 8 of 38
  • CVE-2026-22734HigApr 17, 2026
    risk 0.56cvss 8.6epss 0.00

    Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that…

  • CVE-2025-7448HigSep 12, 2025
    risk 0.56cvss —epss 0.00

    Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack

  • CVE-2023-50224MedKEVMay 3, 2024
    risk 0.56cvss 6.5epss 0.16

    TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit…

  • CVE-2025-31170HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58127HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58126HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58125HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58124HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-30191HigApr 9, 2024
    risk 0.55cvss 8.4epss 0.00

    A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA…

  • CVE-2025-25182CriFeb 12, 2025
    risk 0.54cvss 9.4epss 0.01

    Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a…

  • CVE-2024-1555HigFeb 20, 2024
    risk 0.54cvss 8.3epss 0.00

    When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

  • CVE-2023-6263HigNov 22, 2023
    risk 0.54cvss 8.3epss 0.00

    An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate…

  • CVE-2023-3243HigJun 28, 2023
    risk 0.54cvss 8.3epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version…

  • CVE-2021-28372HigAug 17, 2021
    risk 0.54cvss 8.3epss 0.03

    ThroughTek's Kalay Platform 2.0 network allows an attacker to impersonate an arbitrary ThroughTek (TUTK) device given a valid 20-byte uniquely assigned identifier (UID). This could result in an attacker hijacking a victim's connection and forcing them into supplying credentials…

  • CVE-2017-8422HigMay 17, 2017
    risk 0.54cvss 7.8epss 0.02

    KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.

  • CVE-2026-82228HigAug 31, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

  • CVE-2026-76356HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation…

  • CVE-2026-65570HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.

  • CVE-2026-48063CriAug 3, 2026
    risk 0.53cvss —epss 0.00

    Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This…

  • CVE-2026-12382HigJul 15, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can…