CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

576 vulnerabilities with CWE-290
CVE-2023-51747 HIGH
Apache James <3.8.1-3.7.5 - SMTP Smuggling
CVSS 7.1
CVE-2023-42889 MEDIUM
macOS 12.0-12.7.1 - Authentication Bypass by Spoofing
CVSS 5.5
CVE-2023-42843 MEDIUM
Safari < 17.1 - Address Bar Spoofing via Inconsistent UI State
CVSS 4.3
CVE-2023-7169 MEDIUM
Snow Inventory Agent < 7.0 - Authentication Bypass via Signature Spoofing
CVSS 6.0
CVE-2023-6044 MEDIUM
Lenovo Vantage - Privilege Escalation
CVSS 6.3
CVE-2023-4566 HIGH
Trust Relationship Inaccuracy - Info Disclosure
CVSS 7.5
CVE-2023-44117 HIGH
Trust Relationship Inaccuracy - Info Disclosure
CVSS 7.5
CVE-2023-4001 MEDIUM
GRUB2 - Authentication Bypass via Duplicate UUID Configuration File
CVSS 6.8
CVE-2023-51350 CRITICAL
ujcms 8.0.2 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
CVE-2023-41069 MEDIUM
iPadOS < 17.0 - Authentication Bypass via Face ID Spoofing
CVSS 5.5
CVE-2023-49794 MEDIUM
kernelsu < 0.7.1 - Authentication Bypass via Malicious APK Spoofing
CVSS 6.7
CVE-2023-35622 HIGH
Windows Server 2008, 2012, 2016, 2019, 2022, 2022 23H2 - Authentication Bypass via DNS Spoofing
CVSS 7.5
CVE-2023-50463 MEDIUM
Caddy < 0.6.0 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 6.5
CVE-2023-43304 HIGH
PARK DANDAN mini-app - Info Disclosure
CVSS 8.2
CVE-2023-6263 HIGH
Network Optix NxCloud <23.1.0.40440 - Info Disclosure
CVSS 8.3
CVE-2023-3103 HIGH
Unitree A1 Firmware - Authentication Bypass via Man-in-the-Middle Attack
CVSS 8.0
CVE-2023-5801 CRITICAL
HarmonyOS - Authentication Bypass via Face Unlock Module
CVSS 9.1
CVE-2023-36769 MEDIUM
Microsoft OneNote - Authentication Bypass by Spoofing
CVSS 4.6
CVE-2023-20246 MEDIUM
Snort 3.0.0-3.1.56.9 - Unauthenticated Access Control Policy Bypass
CVSS 5.8
CVE-2023-20256 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Access Control List Bypass via Per-User-Override Feature
CVSS 5.0
CVE-2023-20245 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Access Control List Bypass via Per-User-Override Feature
CVSS 5.8
CVE-2023-28803 MEDIUM
Zscaler Client Connector <3.9 - Auth Bypass
CVSS 5.9
CVE-2023-30803 CRITICAL
Sangfor Next-Gen Application Firewall NGAF8.0.17 - Unauthenticated Authentication Bypass via Y-forwarded-for Header
CVSS 9.8
CVE-2023-44463 MEDIUM
pretix < 2023.7.1 - IP Address Spoofing via X-Forwarded-For Header
CVSS 5.3
CVE-2023-41329 LOW
WireMock - DNS Rebinding Attack via Proxy Mode Network Restrictions
CVSS 3.9
Details
Vulnerabilities 576