CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

576 vulnerabilities with CWE-290
CVE-2023-4178 CRITICAL
Neutron Smart VMS < b1130.1.0.1 - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2023-31424 HIGH
Brocade SANnav <2.3.0-2.2.2a - Auth Bypass
CVSS 8.1
CVE-2023-30950 MEDIUM
Palantir Foundry Campaigns Service - Information Disclosure
CVSS 6.5
CVE-2023-38173 MEDIUM
Microsoft Edge Chromium < 115.0.1901.183 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2023-35392 MEDIUM
Microsoft Edge Chromium < 115.0.1901.183 - Authentication Bypass by Spoofing
CVSS 4.7
CVE-2023-34329 CRITICAL
AMI MegaRAC SP-X - Authentication Bypass via HTTP Header Spoofing
CVSS 9.1
CVE-2023-36883 MEDIUM
Microsoft Edge for iOS < 114.0.1823.82 - Spoofing
CVSS 4.3
CVE-2023-27199 MEDIUM
PAX Technology A930 PayDroid - Code Injection
CVSS 6.7
CVE-2023-22814 CRITICAL
Western Digital My Cloud OS 5.02.104-5.26.202 - Authentication Bypass via Token Spoofing
CVSS 10.0
CVE-2023-29147 MEDIUM
Malwarebytes EDR <1.0.11 - Privilege Escalation
CVSS 5.5
CVE-2023-3243 HIGH
Honeywell Alerton BCM-WEB 3.3.X - Authentication Bypass via Session Hash Spoofing
CVSS 8.3
CVE-2023-27964 MEDIUM
AirPods Firmware - Authentication Bypass via Bluetooth Device Spoofing
CVSS 5.4
CVE-2023-3128 CRITICAL
Grafana 6.7.0-8.5.26 and 9.4.0-9.4.12 - Authentication Bypass via Azure AD Email Claim Spoofing
CVSS 9.4
CVE-2023-34167 MEDIUM
Huawei EMUI - Authentication Bypass by Spoofing via Trustlist Manipulation
CVSS 5.3
CVE-2023-34160 MEDIUM
Huawei EMUI - Authentication Bypass by Spoofing via Trustlist Manipulation
CVSS 5.3
CVE-2023-34158 MEDIUM
Huawei EMUI - Authentication Bypass by Spoofing via Trustlist Manipulation
CVSS 5.3
CVE-2023-34157 CRITICAL
HarmonyOS < 2.0 - Authentication Bypass by Spoofing via HwWatchHealth Hijacking
CVSS 10.0
CVE-2023-33140 MEDIUM
Microsoft OneNote - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2023-2807 MEDIUM
Pandora FMS < 772 - Unauthenticated Authentication Bypass via Password Reset Spoofing
CVSS 6.4
CVE-2023-2001 MEDIUM
GitLab < 15.10.8, 15.11 < 15.11.7, 16.0 < 16.0.2 - Authentication Bypass by Spoofing via Protected Tag
CVSS 4.3
CVE-2023-32207 HIGH
Firefox < 113.0 and Firefox ESR < 102.11 - Authentication Bypass via Popup Notification Spoofing
CVSS 8.8
CVE-2023-25743 HIGH
Firefox Focus - Authentication Bypass by Spoofing via Fullscreen Mode
CVSS 7.5
CVE-2023-2887 CRITICAL
Chatbot <4.0.3.4-4.0.3.7 - Auth Bypass
CVSS 9.8
CVE-2023-29334 MEDIUM
Microsoft Edge Chromium < 112.0.1722.48 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2023-24935 MEDIUM
Microsoft Edge Chromium < 112.0.5615.49 - Authentication Bypass by Spoofing
CVSS 6.1
Details
Vulnerabilities 576