CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

575 vulnerabilities with CWE-290
CVE-2024-13685 MEDIUM
Admin and Site Enhancements WordPress Plugin < 7.6.10 - Authentication Bypass via IP Header Spoofing
CVSS 5.3
CVE-2024-36557 MEDIUM
Forever KidsWatch Call Me KW50 and KW60 - Authentication Bypass via IMEI Spoofing
CVSS 6.6
CVE-2024-55925 HIGH
Xerox Workplace Suite - Auth Bypass
CVSS 7.5
CVE-2024-13061 CRITICAL
Electronic Official Document Management System - Auth Bypass
CVSS 9.8
CVE-2024-12108 CRITICAL
WhatsUp Gold 23.1.0-24.0.1 - Authentication Bypass via Public API
CVSS 9.6
CVE-2024-54450 CRITICAL
Kurmi Provisioning Suite 7.9.0.33 - Info Disclosure
CVSS 9.4
CVE-2024-55470 HIGH
Oqtane Framework 6.0.0 - Authentication Bypass via EntityID Parameter Spoofing
CVSS 7.5
CVE-2024-55232 MEDIUM
PHPGurukul Online Notes Sharing Management System 1.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2024-54158 LOW
JetBrains YouTrack <2024.3.52635 - Open Redirect
CVSS 3.5
CVE-2024-50380 HIGH
Snap One OVRC cloud < 7.3 - Authentication Bypass via MAC Address Spoofing
CVE-2024-53862 HIGH
Argo Workflows 3.5.7-3.5.12 - Unauthenticated Workflow Archive Access via Spoofed Token
CVSS 7.5
CVE-2024-36466 HIGH
Zabbix 6.0.0-6.0.31 - Authentication Bypass via Forged zbx_session Cookie
CVSS 8.8
CVE-2024-11701 MEDIUM
Firefox < 133 and Thunderbird < 133 - Authentication Bypass by Spoofing via Address Bar Display
CVSS 4.3
CVE-2024-11692 MEDIUM
Firefox < 133 and ESR < 128.5 - Authentication Bypass by Spoofing via Select Dropdown Overlay
CVSS 4.3
CVE-2024-8935 HIGH
Schneider Electric Modicon M340 CPU, MC80, Momentum Unity M1E - Authentication Bypass via Man-In-The-Middle Attack
CVSS 7.5
CVE-2024-51504 CRITICAL
Apache ZooKeeper 3.9.0-3.9.2 - Authentication Bypass by Spoofing via X-Forwarded-For Header
CVSS 9.1
CVE-2024-51406 MEDIUM
Floodlight SDN Open Flow Controller 1.2 - Authentication Bypass by Spoofing via Fake LLDP Packets
CVSS 6.2
CVE-2024-10465 MEDIUM
Firefox < 132 and ESR < 128.4 - Authentication Bypass by Spoofing via Persistent Clipboard Paste Button
CVSS 6.5
CVE-2024-10462 MEDIUM
Firefox < 132 and ESR < 128.4 - Origin Spoofing via Truncated URL in Permission Prompt
CVSS 6.5
CVE-2024-20384 MEDIUM
Cisco ASA Software - Unauthenticated Access Control Bypass via ACL Logic Error
CVSS 5.8
CVE-2024-20299 MEDIUM
Cisco ASA Software Unauthenticated ACL Bypass via AnyConnect
CVSS 5.8
CVE-2024-20297 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Access Control List Bypass via AnyConnect Session
CVSS 5.8
CVE-2024-8901 HIGH
AWS ALB Route Directive Adapter For Istio - Auth Bypass
CVSS 7.5
CVE-2024-10125 HIGH
Amazon.ApplicationLoadBalancer.Identity.AspNetCore - Info Disclosure
CVSS 7.5
CVE-2024-49214 MEDIUM
HAProxy <3.1-dev7, <3.0.5, <2.9.11 - SSRF
CVSS 5.3
Details
Vulnerabilities 575