CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2022-34716 MEDIUM
.NET 6.0.0-6.0.7 and .NET Core 3.1-3.1.27 - Authentication Bypass by Spoofing
CVSS 5.9
CVE-2022-2324 HIGH
SonicWall Hosted Email Security <10.0.17.7319 - Info Disclosure
CVSS 7.5
CVE-2022-35629 MEDIUM
Velociraptor < 0.6.5-2 - Authentication Bypass by Client ID Spoofing
CVSS 5.4
CVE-2022-30319 HIGH
Honeywell Saia PG5 Controls Suite - Authentication Bypass via S-Bus UDP Spoofing
CVSS 8.1
CVE-2022-2310 CRITICAL
Skyhigh SWG <10.2.12-11.2.1 - Auth Bypass
CVSS 10.0
CVE-2022-1495 MEDIUM
Google Chrome < 101.0.4951.41 - Authentication Bypass by Spoofing via APK Downloads Dialog
CVSS 4.3
CVE-2022-1307 MEDIUM
Google Chrome < 100.0.4896.88 - URL Spoofing via Full Screen Mode
CVSS 4.3
CVE-2022-1306 MEDIUM
Google Chrome < 100.0.4896.88 - URL Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2022-1129 MEDIUM
Google Chrome < 100.0.4896.60 - URL Spoofing via Full Screen Mode
CVSS 6.5
CVE-2022-2368 MEDIUM
microweber < 1.2.20 - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2022-22476 HIGH
IBM WebSphere App Server <22.0.0.7 - Auth Bypass
CVSS 8.8
CVE-2022-1745 MEDIUM
Dominion Voting Systems ImageCast X - Authentication Bypass via Physical Access
CVSS 6.8
CVE-2022-32983 MEDIUM
Knot Resolver <5.5.1 - Info Disclosure
CVSS 5.3
CVE-2022-29165 CRITICAL
Argo CD <2.1.15-2.3.4 - Auth Bypass
CVSS 10.0
CVE-2022-29218 HIGH
RubyGems.org - Authentication Bypass by Spoofing via Gem Upload Platform Handling
CVSS 7.7
CVE-2022-25989 HIGH
Anker Eufy Homebase 2 <2.1.8.5h - Auth Bypass
CVSS 8.8
CVE-2022-24858 MEDIUM
next-auth < 3.29.2 and 4.0.0-4.3.1 - Authentication Bypass via Redirect Callback
CVSS 6.1
CVE-2022-26910 MEDIUM
Skype for Business Server - Authentication Bypass by Spoofing
CVSS 5.3
CVE-2022-26505 HIGH
ReadyMedia <1.3.1 - Info Disclosure
CVSS 7.4
CVE-2022-21142 CRITICAL
a-blog cms 2.8.0-2.8.73, 2.9.0-2.9.38, 2.10.0-2.10.42, 2.11.0-2.11.40 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2022-24112 CRITICAL KEV
APISIX Admin API default access token RCE
CVSS 9.8
CVE-2022-23131 CRITICAL KEV
Zabbix 5.4.0-5.4.7 - Unauthenticated Authentication Bypass via SAML Session Spoofing
CVSS 9.1
CVE-2021-47923 CRITICAL
OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
CVSS 9.8
CVE-2021-25827 CRITICAL
Emby < 4.7.12.0 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
CVE-2021-45036 HIGH
Velneo vClient 28.1.3 - Authentication Bypass by Spoofing via Hashed Password
CVSS 8.7
Details
Vulnerabilities 637