CWE-290— Authentication Bypass by Spoofing
534 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-290page 4 of 11
- CVE-2022-24858MEDIUMCVSS 6.1EG 6.12022-04-19
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add…
- CVE-2022-25989HIGHCVSS 8.8EG 8.82022-05-05
An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this v…
- CVE-2022-26505HIGHCVSS 7.4EG 7.42022-03-06
A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.
- CVE-2022-26910MEDIUMCVSS 5.3EG 5.32022-04-15
Skype for Business and Lync Spoofing Vulnerability
- CVE-2022-26925HIGHCVSS 8.1EG 9.0⚠ KEV2022-05-10
Windows LSA Spoofing Vulnerability
- CVE-2022-29165CRITICALCVSS 10.0EG 10.02022-05-20
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions 2.1.15, 2.2.9, and 2.3.4 which would allow unauthenticated …
- CVE-2022-29218HIGHCVSS 7.7EG 7.72022-05-13
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily…
- CVE-2022-30319HIGHCVSS 8.1EG 8.12022-07-28
Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a Saia Burgess Controls (SBC) PCD S-Bus authentication bypass issue. The affected components are characterized as: S-Bus…
- CVE-2022-31149HIGHCVSS 8.8EG 8.82022-09-07
ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. This vulnerability impacts everyone running ActivityWatch and gives the attacker full access to the ActivityWatch REST AP…
- CVE-2022-31738MEDIUMCVSS 6.5EG 6.52022-12-22
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Fi…
- CVE-2022-3180CRITICALCVSS 9.8EG 9.82025-02-11
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.
- CVE-2022-32744HIGHCVSS 8.8EG 8.82022-08-25
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
- CVE-2022-32747HIGHCVSS 8.0EG 8.12023-01-30
A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxu…
- CVE-2022-32983MEDIUMCVSS 5.3EG 5.32022-06-20
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.
- CVE-2022-3337MEDIUMCVSS 6.7EG 6.72022-10-28
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch fe…
- CVE-2022-33991MEDIUMCVSS 5.3EG 5.32022-08-15
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
- CVE-2022-34689HIGHCVSS 7.5EG 7.52022-10-11
Windows CryptoAPI Spoofing Vulnerability
- CVE-2022-34716MEDIUMCVSS 5.9EG 5.92022-08-09
.NET Spoofing Vulnerability
- CVE-2022-35629MEDIUMCVSS 5.4EG 5.42022-07-29
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issu…
- CVE-2022-35770MEDIUMCVSS 6.5EG 6.52022-10-11
Windows NTLM Spoofing Vulnerability
- CVE-2022-35957MEDIUMCVSS 6.6EG 6.62022-09-20
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin acc…
- CVE-2022-36331CRITICALCVSS 10.0EG 10.02023-06-12
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devic…
- CVE-2022-37709MEDIUMCVSS 5.3EG 5.32022-09-16
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attac…
- CVE-2022-38164MEDIUMCVSS 6.5EG 6.52022-11-07
A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only display certain part of the entire URL.
- CVE-2022-3820MEDIUMCVSS 6.5EG 6.52023-01-26
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were con…
- CVE-2022-38712MEDIUMCVSS 5.9EG 5.92022-11-03
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
- CVE-2022-39227CRITICALCVSS 9.1EG 9.12022-09-23
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obta…
- CVE-2022-40269MEDIUMCVSS 6.8EG 8.12023-02-02
Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.14.000 to 01.47.000, Mitsubishi Electric Corporation GOT2000 Series GT25 model versions 01.14.000 to 01.47.000 and Mit…
- CVE-2022-4098HIGHCVSS 8.0EG 7.12022-12-13
Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session …
- CVE-2022-41798MEDIUMCVSS 6.5EG 6.52022-12-05
Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected p…
- CVE-2022-42983HIGHCVSS 8.8EG 8.82022-10-17
anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens.
- CVE-2022-4303HIGHCVSS 7.5EG 7.52023-01-23
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms.
- CVE-2022-44636MEDIUMCVSS 4.6EG 4.62022-12-13
The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 model…
- CVE-2022-44713HIGHCVSS 7.5EG 7.52022-12-13
Microsoft Outlook for Mac Spoofing Vulnerability
- CVE-2022-4550HIGHCVSS 7.5EG 7.52023-02-27
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
- CVE-2022-4746HIGHCVSS 7.5EG 7.52023-01-23
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.
- CVE-2022-47522HIGHCVSS 7.5EG 7.52023-04-15
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sendi…
- CVE-2022-47648HIGHCVSS 7.6EG 8.82023-02-08
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publi…
- CVE-2022-48349CRITICALCVSS 9.1EG 9.12023-03-27
The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability.
- CVE-2022-48469MEDIUMCVSS 6.5EG 6.52023-06-16
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers.
- CVE-2022-48513CRITICALCVSS 9.8EG 9.82023-07-06
Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.
- CVE-2023-0816MEDIUMCVSS 6.5EG 6.52023-03-27
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
- CVE-2023-2001MEDIUMCVSS 4.3EG 4.32023-06-07
An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker was able to spoof protected tags, which could p…
- CVE-2023-20025CRITICALCVSS 9.0EG 9.82023-01-20
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is …
- CVE-2023-20245MEDIUMCVSS 5.8EG 5.82023-11-01
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access c…
- CVE-2023-20246MEDIUMCVSS 5.8EG 5.82023-11-01
Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic…
- CVE-2023-20256MEDIUMCVSS 5.0EG 5.02023-11-01
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access c…
- CVE-2023-21794MEDIUMCVSS 4.3EG 4.32023-02-14
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2023-22474HIGHCVSS 8.7EG 8.72023-02-03
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server uses the request header `x-forwarded-for` to determine the client IP address. If Parse Server doesn't run behind a proxy s…
- CVE-2023-22814CRITICALCVSS 10.0EG 10.02023-07-01
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.
Map vulnerabilities like CWE-290 to your infrastructure
EchelonGraph correlates every CVE — across CWE-290 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →