VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 9 of 34
  • CVE-2026-34457CriApr 14, 2026
    risk 0.52cvss 9.1epss 0.00

    OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and…

  • CVE-2025-54576CriJul 30, 2025
    risk 0.52cvss 9.1epss 0.01

    OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using the skip_auth_routes…

  • CVE-2025-24895CriFeb 18, 2025
    risk 0.52cvss 9.1epss 0.01

    CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. Identity Provider (IDP): the system that authenticates users and provides identity information (SAML…

  • CVE-2025-24894CriFeb 18, 2025
    risk 0.52cvss 9.1epss 0.01

    SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider (IDP): the system that authenticates users and provides identity information (SAML…

  • CVE-2024-51504CriNov 7, 2024
    risk 0.52cvss 9.1epss 0.01

    When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default configuration of client's IP address detection…

  • CVE-2023-48396CriJul 30, 2024
    risk 0.52cvss 9.1epss 0.01

    Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a…

  • CVE-2024-27349CriApr 22, 2024
    risk 0.52cvss 9.1epss 0.01

    Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

  • CVE-2023-3103HigNov 22, 2023
    risk 0.52cvss 8.0epss 0.01

    Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In addition, if a MITM attack is carried out, it is possible to consume the robot's resources, which could…

  • CVE-2022-32747HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.00

    A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE)…

  • CVE-2022-4098HigDec 13, 2022
    risk 0.52cvss 8.0epss 0.00

    Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change…

  • CVE-2022-34689HigOct 11, 2022
    risk 0.52cvss 7.5epss 0.38

    Windows CryptoAPI Spoofing Vulnerability

  • CVE-2022-39227CriSep 23, 2022
    risk 0.52cvss 9.1epss 0.04

    python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its…

  • CVE-2021-42320HigDec 15, 2021
    risk 0.52cvss 8.0epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-38598CriAug 23, 2021
    risk 0.52cvss 9.1epss 0.01

    OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to…

  • CVE-2026-59916HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code…

  • CVE-2026-46731HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary…

  • CVE-2026-31889HigMar 11, 2026
    risk 0.51cvss 8.9epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow…

  • CVE-2025-13455HigJan 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.

  • CVE-2025-54305HigDec 4, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or…

  • CVE-2021-40867HigSep 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker who uses the same source IP address as an admin in the process of logging in (e.g., behind the same NAT device, or already in possession of a…