CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2024-11692 MEDIUM
Firefox < 133 and ESR < 128.5 - Authentication Bypass by Spoofing via Select Dropdown Overlay
CVSS 4.3
CVE-2024-8935 HIGH
Schneider Electric Modicon M340 CPU, MC80, Momentum Unity M1E - Authentication Bypass via Man-In-The-Middle Attack
CVSS 7.5
CVE-2024-51504 CRITICAL
Apache ZooKeeper 3.9.0-3.9.2 - Authentication Bypass by Spoofing via X-Forwarded-For Header
CVSS 9.1
CVE-2024-51406 MEDIUM
Floodlight SDN Open Flow Controller 1.2 - Authentication Bypass by Spoofing via Fake LLDP Packets
CVSS 6.2
CVE-2024-10465 MEDIUM
Firefox < 132 and ESR < 128.4 - Authentication Bypass by Spoofing via Persistent Clipboard Paste Button
CVSS 6.5
CVE-2024-10462 MEDIUM
Firefox < 132 and ESR < 128.4 - Origin Spoofing via Truncated URL in Permission Prompt
CVSS 6.5
CVE-2024-20384 MEDIUM
Cisco ASA Software - Unauthenticated Access Control Bypass via ACL Logic Error
CVSS 5.8
CVE-2024-20299 MEDIUM
Cisco ASA Software Unauthenticated ACL Bypass via AnyConnect
CVSS 5.8
CVE-2024-20297 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Access Control List Bypass via AnyConnect Session
CVSS 5.8
CVE-2024-8901 HIGH
AWS ALB Route Directive Adapter For Istio - Auth Bypass
CVSS 7.5
CVE-2024-10125 HIGH
Amazon.ApplicationLoadBalancer.Identity.AspNetCore - Info Disclosure
CVSS 7.5
CVE-2024-49214 MEDIUM
HAProxy <3.1-dev7, <3.0.5, <2.9.11 - SSRF
CVSS 5.3
CVE-2024-49193 HIGH
Zendesk <2024-07-02 - Info Disclosure
CVSS 7.5
CVE-2024-45397 MEDIUM
h2o HTTP Server - Spoofed Source Access Control Bypass
CVSS 5.9
CVE-2024-9391 MEDIUM
Firefox Focus for Android < 131.0 - Authentication Bypass by Spoofing via Full-Screen Mode
CVSS 6.5
CVE-2024-46957 CRITICAL
mellium.im/xmpp 0.0.1-0.21.4 - Authentication Bypass via Predictable ID Spoofing
CVSS 9.8
CVE-2024-39341 MEDIUM
Entrust Instant Financial Issuance (On Premise) Software - Info Dis...
CVSS 5.9
CVE-2024-45453 LOW
Peter Hardy-vanDoorn Maintenance Redirect <2.0.1 - Auth Bypass
CVSS 3.7
CVE-2024-8908 MEDIUM
Google Chrome < 129.0.6668.58 - UI Spoofing via Autofill
CVSS 4.3
CVE-2024-6678 CRITICAL
GitLab CE/EE <17.1.7-17.3.2 - Privilege Escalation
CVSS 9.9
CVE-2024-44104 HIGH
Ivanti Workspace Control < 10.18.99.0 - Authenticated Privilege Escalation via Authentication Spoofing
CVSS 8.8
CVE-2024-8399 MEDIUM
Firefox Focus < 130.0 - URL Spoofing via JavaScript Links
CVSS 4.7
CVE-2024-8386 MEDIUM
Firefox < 130- Thunderbird < 128.2 - XSS
CVSS 6.1
CVE-2024-43944 LOW
Yassine Idrissi Maintenance & Coming Soon Redirect Animation <2.1.3...
CVSS 3.7
CVE-2024-7745 MEDIUM
WS_FTP Server <8.8.8 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 637