CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2022-47648 HIGH
Bosch B420 Firmware - Unauthenticated Control Panel Access via IP-Based Authorization Bypass
CVSS 7.6
CVE-2022-40269 MEDIUM
Mitsubishi Electric GOT2000 Series and GT SoftGOT2000 - Authentication Bypass by Spoofing via HTML Attribute Abuse
CVSS 6.8
CVE-2022-32747 HIGH
EcoStruxure Cybersecurity Admin Expert < 2.4 - Authentication Bypass by Spoofing
CVSS 8.0
CVE-2022-3820 MEDIUM
GitLab <15.4.4-15.5.2 - Auth Bypass
CVSS 6.5
CVE-2022-4746 HIGH
FluentAuth < 1.0.2 - Authentication Bypass via HTTP Header Spoofing
CVSS 7.5
CVE-2022-4303 HIGH
WP Limit Login Attempts <2.6.4 - Auth Bypass
CVSS 7.5
CVE-2022-31738 MEDIUM
Firefox < 101 and Firefox ESR < 91.10 - Authentication Bypass by Spoofing via Fullscreen Mode Exit
CVSS 6.5
CVE-2022-44713 HIGH
Microsoft Office - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2022-44636 MEDIUM
Samsung TV 2021-2022 Models - Authentication Bypass via Bluetooth Spoofing
CVSS 4.6
CVE-2022-4098 HIGH
Wiesemann&Theis ComServer - Auth Bypass
CVSS 8.0
CVE-2022-41798 MEDIUM
Kyocera Document Solutions - Info Disclosure
CVSS 6.5
CVE-2022-38164 MEDIUM
F-Secure SAFE < 19.0 - URL Spoofing via Phishing Attack
CVSS 6.5
CVE-2022-38712 MEDIUM
IBM WebSphere Application Server - SOAPAction Spoofing
CVSS 5.9
CVE-2022-3337 MEDIUM
WARP mobile client - Info Disclosure
CVSS 6.7
CVE-2022-42983 HIGH
anji-plus AJ-Report 0.9.8.6 - Authentication Bypass via JWT Token Spoofing
CVSS 8.8
CVE-2022-0030 HIGH
PAN-OS 8.1.0-8.1.23 - Authentication Bypass via Web Interface Impersonation
CVSS 8.1
CVE-2022-35770 MEDIUM
Windows NTLM Spoofing - Privilege Escalation
CVSS 6.5
CVE-2022-34689 HIGH
Windows CryptoAPI - Authentication Bypass by Spoofing
CVSS 7.5
CVE-2022-39227 CRITICAL
python-jwt < 3.3.4 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2022-23949 HIGH
Keylime < 6.3.0 - Log Spoofing via Unsanitized UUID
CVSS 7.5
CVE-2022-35957 MEDIUM
Grafana <9.1.6, 8.5.13 - Privilege Escalation
CVSS 6.6
CVE-2022-37709 MEDIUM
Tesla Model 3 Firmware V11.0(2022.4.5.1 6b701552d7a6) - Authentication Bypass via BLE Phone Key Spoofing
CVSS 5.3
CVE-2022-31149 HIGH
ActivityWatch < 0.12.0b2 - Authentication Bypass via DNS Rebinding
CVSS 8.8
CVE-2022-32744 HIGH
Samba 4.3.0-4.14.13 - Authentication Bypass via Kpasswd Request Spoofing
CVSS 8.8
CVE-2022-33991 MEDIUM
dproxy-nexgen - DNSSEC Protection Bypass via CD Bit Spoofing
CVSS 5.3
Details
Vulnerabilities 637