BaseIncomplete
CWE-290Authentication Bypass by Spoofing
Category: auth
Description
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Common consequences· 1
- Access Control — Bypass Protection Mechanism, Gain Privileges or Assume IdentityThis weakness can allow an attacker to access resources which are not otherwise accessible without proper authentication.
Related CAPEC attack patterns· 10
References
Exploits (incoming)10
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Exploiting Trust in Clientcapec-22 | 100% | live |
| AttackPattern | Exploitation of Trusted Identifierscapec-21 | 100% | live |
| AttackPattern | Reusing Session IDs (aka Session Replay)capec-60 | 100% | live |
| AttackPattern | Signature Spoofcapec-473 | 100% | live |
| AttackPattern | Web Services API Signature Forgery Leveraging Hash Function Extension Weaknesscapec-461 | 100% | live |
| AttackPattern | Session Credential Falsification through Predictioncapec-59 | 100% | live |
| AttackPattern | Signature Spoofing by Misrepresentationcapec-476 | 100% | live |
| AttackPattern | Bluetooth Impersonation AttackS (BIAS)capec-667 | 100% | live |
| AttackPattern | Adversary in the Middle (AiTM)capec-94 | 100% | live |
| AttackPattern | Creating a Rogue Certification Authority Certificatecapec-459 | 100% | live |
Compliance frameworks addressing this (incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | owasp_api_top10-api02 | 100% | live |
(incoming)60
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-1104cve-2025-1104 | 0% | live |
| Vulnerability | CVE-2025-11209cve-2025-11209 | 0% | live |
| Vulnerability | CVE-2025-11250cve-2025-11250 | 0% | live |
| Vulnerability | CVE-2025-1298cve-2025-1298 | 0% | live |
| Vulnerability | CVE-2025-21415cve-2025-21415 | 0% | live |
| Vulnerability | CVE-2025-2188cve-2025-2188 | 0% | live |
| Vulnerability | CVE-2025-23168cve-2025-23168 | 0% | live |
| Vulnerability | CVE-2025-25182cve-2025-25182 | 0% | live |
| Vulnerability | CVE-2025-27616cve-2025-27616 | 0% | live |
| Vulnerability | CVE-2025-27671cve-2025-27671 | 0% | live |
| Vulnerability | CVE-2025-30142cve-2025-30142 | 0% | live |
| Vulnerability | CVE-2025-31170cve-2025-31170 | 0% | live |
| Vulnerability | CVE-2025-32966cve-2025-32966 | 0% | live |
| Vulnerability | CVE-2025-36119cve-2025-36119 | 0% | live |
| Vulnerability | CVE-2025-36594cve-2025-36594 | 0% | live |
| Vulnerability | CVE-2025-36753cve-2025-36753 | 0% | live |
| Vulnerability | CVE-2025-43245cve-2025-43245 | 0% | live |
| Vulnerability | CVE-2025-48906cve-2025-48906 | 0% | live |
| Vulnerability | CVE-2025-49002cve-2025-49002 | 0% | live |
| Vulnerability | CVE-2025-54576cve-2025-54576 | 0% | live |
| Vulnerability | CVE-2025-56449cve-2025-56449 | 0% | live |
| Vulnerability | CVE-2025-59385cve-2025-59385 | 0% | live |
| Vulnerability | CVE-2025-59706cve-2025-59706 | 0% | live |
| Vulnerability | CVE-2025-59707cve-2025-59707 | 0% | live |
| Vulnerability | CVE-2025-62235cve-2025-62235 | 0% | live |
| Vulnerability | CVE-2025-66570cve-2025-66570 | 0% | live |
| Vulnerability | CVE-2025-67298cve-2025-67298 | 0% | live |
| Vulnerability | CVE-2025-69203cve-2025-69203 | 0% | live |
| Vulnerability | CVE-2025-69258cve-2025-69258 | 0% | live |
| Vulnerability | CVE-2025-71056cve-2025-71056 | 0% | live |
Showing top 30 of 60 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.