CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2023-6263 HIGH
Network Optix NxCloud <23.1.0.40440 - Info Disclosure
CVSS 8.3
CVE-2023-3103 HIGH
Unitree A1 Firmware - Authentication Bypass via Man-in-the-Middle Attack
CVSS 8.0
CVE-2023-5801 CRITICAL
HarmonyOS - Authentication Bypass via Face Unlock Module
CVSS 9.1
CVE-2023-36769 MEDIUM
Microsoft OneNote - Authentication Bypass by Spoofing
CVSS 4.6
CVE-2023-20246 MEDIUM
Snort 3.0.0-3.1.56.9 - Unauthenticated Access Control Policy Bypass
CVSS 5.8
CVE-2023-20256 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Access Control List Bypass via Per-User-Override Feature
CVSS 5.0
CVE-2023-20245 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Access Control List Bypass via Per-User-Override Feature
CVSS 5.8
CVE-2023-28803 MEDIUM
Zscaler Client Connector <3.9 - Auth Bypass
CVSS 5.9
CVE-2023-30803 CRITICAL
Sangfor Next-Gen Application Firewall NGAF8.0.17 - Unauthenticated Authentication Bypass via Y-forwarded-for Header
CVSS 9.8
CVE-2023-44463 MEDIUM
pretix < 2023.7.1 - IP Address Spoofing via X-Forwarded-For Header
CVSS 5.3
CVE-2023-41329 LOW
WireMock - DNS Rebinding Attack via Proxy Mode Network Restrictions
CVSS 3.9
CVE-2023-4178 CRITICAL
Neutron Smart VMS < b1130.1.0.1 - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2023-31424 HIGH
Brocade SANnav <2.3.0-2.2.2a - Auth Bypass
CVSS 8.1
CVE-2023-30950 MEDIUM
Palantir Foundry Campaigns Service - Information Disclosure
CVSS 6.5
CVE-2023-38173 MEDIUM
Microsoft Edge Chromium < 115.0.1901.183 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2023-35392 MEDIUM
Microsoft Edge Chromium < 115.0.1901.183 - Authentication Bypass by Spoofing
CVSS 4.7
CVE-2023-34329 CRITICAL
AMI MegaRAC SP-X - Authentication Bypass via HTTP Header Spoofing
CVSS 9.1
CVE-2023-36883 MEDIUM
Microsoft Edge for iOS < 114.0.1823.82 - Spoofing
CVSS 4.3
CVE-2023-27199 MEDIUM
PAX Technology A930 PayDroid - Code Injection
CVSS 6.7
CVE-2023-22814 CRITICAL
Western Digital My Cloud OS 5.02.104-5.26.202 - Authentication Bypass via Token Spoofing
CVSS 10.0
CVE-2023-29147 MEDIUM
Malwarebytes EDR <1.0.11 - Privilege Escalation
CVSS 5.5
CVE-2023-3243 HIGH
Honeywell Alerton BCM-WEB 3.3.X - Authentication Bypass via Session Hash Spoofing
CVSS 8.3
CVE-2023-27964 MEDIUM
AirPods Firmware - Authentication Bypass via Bluetooth Device Spoofing
CVSS 5.4
CVE-2023-3128 CRITICAL
Grafana 6.7.0-8.5.26 and 9.4.0-9.4.12 - Authentication Bypass via Azure AD Email Claim Spoofing
CVSS 9.4
CVE-2023-34167 MEDIUM
Huawei EMUI - Authentication Bypass by Spoofing via Trustlist Manipulation
CVSS 5.3
Details
Vulnerabilities 637