CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2021-27862 MEDIUM
IEEE 802.2 < 802.2h-1997 - Authentication Bypass via LLC/SNAP Header Spoofing
CVSS 4.7
CVE-2021-27861 MEDIUM
IEEE 802.2 < 802.2h-1997 - Authentication Bypass via LLC/SNAP Header Spoofing
CVSS 4.7
CVE-2021-27854 MEDIUM
IEEE 802.2 < 802.2h-1997 - Authentication Bypass via VLAN 0 and LLC/SNAP Header Spoofing
CVSS 4.7
CVE-2021-27853 MEDIUM
IEEE 802.2 < 802.2h-1997 - Authentication Bypass via VLAN 0 and LLC/SNAP Header Spoofing
CVSS 4.7
CVE-2021-43310 CRITICAL
Keylime < 6.3.0 - Authentication Bypass and Remote Code Execution via Key Reset Request
CVSS 9.8
CVE-2021-42320 HIGH
Microsoft SharePoint Server - Authentication Bypass by Spoofing
CVSS 8.0
CVE-2021-43807 HIGH
Opencast < 9.10 - HTTP Method Spoofing via URL Parameter
CVSS 7.5
CVE-2021-40288 HIGH
TP-Link Archer AX10 < V1_211014 DoS via Spoofed WPA2/WPA3-SAE Frames
CVSS 7.5
CVE-2021-43220 LOW
Microsoft Edge for iOS < 96.0.1054.29 - Spoofing
CVSS 3.1
CVE-2021-42308 LOW
Microsoft Edge Chromium < 96.0.1054.29 - Authentication Bypass by Spoofing
CVSS 3.1
CVE-2021-41130 MEDIUM
Google Extensible Service Proxy ESPv1 - JWT Claim Header Authorization Bypass
CVSS 6.4
CVE-2021-41753 HIGH
D-Link DIR-X1560 and DIR-X6060 Firmware - Denial of Service via Spoofed SAE Authentication Frames
CVSS 7.5
CVE-2021-40824 MEDIUM
Element Android <1.2.2 - Info Disclosure
CVSS 5.9
CVE-2021-40823 MEDIUM
Matrix Javascript SDK <12.4.1 - Info Disclosure
CVSS 5.9
CVE-2021-40867 HIGH
NETGEAR smart switches <1.0.8.2 - Auth Bypass
CVSS 7.8
CVE-2021-30621 MEDIUM
Chromium - XSS
CVSS 6.5
CVE-2021-30619 MEDIUM
Chromium - XSS
CVSS 6.5
CVE-2021-34646 CRITICAL
Booster for WooCommerce <= 5.4.3 - Authentication Bypass via Email Verification Token Weakness
CVSS 9.8
CVE-2021-32076 MEDIUM
SolarWinds Web Help Desk < 12.7.2 - Authentication Bypass via Referrer Spoofing
CVSS 5.3
CVE-2021-38598 CRITICAL
OpenStack Neutron <16.4.1-18.0.0 - DoS
CVSS 9.1
CVE-2021-28372 HIGH
ThroughTek Kalay Platform 2.0 - Privilege Escalation
CVSS 8.3
CVE-2021-32631 MEDIUM
nimble-project common - Authentication Bypass via JWT Signature Spoofing
CVSS 6.5
CVE-2021-34466 MEDIUM
Windows 10 - Authentication Bypass via Windows Hello Security Feature
CVSS 5.7
CVE-2021-22779 CRITICAL
Schneider-electric Ecostruxure Control Expert < 15.0 - Authentication Bypass by Spoofing
CVSS 9.1
CVE-2021-34548 HIGH
Tor < 0.3.5.15 - Authentication Bypass via Forged RELAY_END or RELAY_RESOLVED
CVSS 7.5
Details
Vulnerabilities 637