CWE-290
690 CVEs • Abstraction: Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CVEs (690)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Samsung 15T Ksu2eakuc Firmware T Ksu2edeuc FirmwareT Ksu2euab Firmware+12 moreJun 17, 2026 Dec 13, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E917...Show more |
1Wut 16Com Server ++ Firmware Com Server 20ma FirmwareCom Server Highspeed 100basefx Firmware+13 moreJun 17, 2026 Dec 13, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can...Show more |
1Kyocera 38Ecosys M2535dn Firmware Ecosys M6526cdn FirmwareEcosys M6526cidn Firmware+35 moreJun 17, 2026 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session info...Show more |
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server. |
A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attack with URL spoofing as the browser only display certain part of the entire URL. |
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762." |
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lo...Show more |
anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens. |
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PA...Show more |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Oct 11, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows NTLM Spoofing Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Oct 11, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows CryptoAPI Spoofing Vulnerability |
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers). |
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers) |
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse. |
3Cisco IeeeIetf96Catalyst 6503 E Firmware Catalyst 6504 E FirmwareCatalyst 6506 E Firmware+93 moreJun 17, 2026 Sep 27, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. |
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. A...Show more |
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar. |
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution. |
2Fedoraproject Grafana2Fedora GrafanaJun 17, 2026 Sep 20, 2022 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over t...Show more |
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE chann...Show more |