CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2023-34160 MEDIUM
Huawei EMUI - Authentication Bypass by Spoofing via Trustlist Manipulation
CVSS 5.3
CVE-2023-34158 MEDIUM
Huawei EMUI - Authentication Bypass by Spoofing via Trustlist Manipulation
CVSS 5.3
CVE-2023-34157 CRITICAL
HarmonyOS < 2.0 - Authentication Bypass by Spoofing via HwWatchHealth Hijacking
CVSS 10.0
CVE-2023-33140 MEDIUM
Microsoft OneNote - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2023-2807 MEDIUM
Pandora FMS < 772 - Unauthenticated Authentication Bypass via Password Reset Spoofing
CVSS 6.4
CVE-2023-2001 MEDIUM
GitLab < 15.10.8, 15.11 < 15.11.7, 16.0 < 16.0.2 - Authentication Bypass by Spoofing via Protected Tag
CVSS 4.3
CVE-2023-32207 HIGH
Firefox < 113.0 and Firefox ESR < 102.11 - Authentication Bypass via Popup Notification Spoofing
CVSS 8.8
CVE-2023-25743 HIGH
Firefox Focus - Authentication Bypass by Spoofing via Fullscreen Mode
CVSS 7.5
CVE-2023-2887 CRITICAL
Chatbot <4.0.3.4-4.0.3.7 - Auth Bypass
CVSS 9.8
CVE-2023-29334 MEDIUM
Microsoft Edge Chromium < 112.0.1722.48 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2023-24935 MEDIUM
Microsoft Edge Chromium < 112.0.5615.49 - Authentication Bypass by Spoofing
CVSS 6.1
CVE-2023-0816 MEDIUM
Formidable Forms WordPress Plugin < 6.1 - IP Address Spoofing via Untrusted Headers
CVSS 6.5
CVE-2023-24892 HIGH
Microsoft Edge Chromium < 111.0.1661.41 - Authentication Bypass by Spoofing via Webview2
CVSS 8.2
CVE-2023-23398 HIGH
Microsoft Excel - Authentication Bypass by Spoofing
CVSS 7.1
CVE-2023-21794 MEDIUM
Microsoft Edge Chromium < 110.0.1587.41 - Authentication Bypass by Spoofing
CVSS 4.3
CVE-2023-22474 HIGH
parse-server < 5.4.1 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 8.7
CVE-2023-20025 CRITICAL
Cisco Small Business RV016-082 - Auth Bypass
CVSS 9.0
CVE-2022-3180 CRITICAL
wpgateway <= 3.5 - Unauthenticated Privilege Escalation via Administrator Account Creation
CVSS 9.8
CVE-2022-22364 MEDIUM
IBM Cognos Controller <11.0.0 - SSRF
CVSS 5.3
CVE-2022-48513 CRITICAL
Huawei EMUI and HarmonyOS - Authentication Bypass in Gallery Module
CVSS 9.8
CVE-2022-48469 MEDIUM
Huawei B535-232a Firmware - Traffic Hijacking via Authentication Bypass
CVSS 6.5
CVE-2022-36331 CRITICAL
Western Digital My Cloud <5.25.132, <8.13.1-102 - Info Disclosure
CVSS 10.0
CVE-2022-47522 HIGH
IEEE 802.11 through 802.11ax - Authentication Bypass by MAC Address Spoofing
CVSS 7.5
CVE-2022-48349 CRITICAL
Huawei EMUI and HarmonyOS - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2022-4550 HIGH
User Activity WP <1.0.1 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 637