Authentication Bypass by Spoofing (CWE-290)
CWE-290 is an attack-focused Base weakness caused by authentication schemes that are open to spoofing. Its authentication can be satisfied with spoofed information instead of a real proof of identity. Related children include reliance on IP addresses (CWE-291) and on reverse DNS (CWE-350).
About CWE-290
The weakness can let an attacker reach resources that should require proper authentication, or assume another identity.
Mitigations
- +Use identity verification that cannot simply be spoofed, such as credentials or certificates, instead of source IP address (CWE-291).
- +Do not rely on reverse DNS names for security decisions (CWE-350).
- +Where DNS names are used, perform both forward and reverse lookups to detect DNS spoofing (CWE-350).
CWE-290 Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2023-50224 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability | TP-Link | 6.5 | 15.6% | KEV | 2024-05-03 |
| CVE-2024-54085 | Redfish Authentication Bypass | AMI | 10.0 | 60.7% | KEV | 2025-03-11 |
| CVE-2024-4358 | Registration Authentication Bypass Vulnerability | Progress Software Corporation | 9.8 | 97.5% | KEV | 2024-05-29 |
| CVE-2022-24112 | apisix/batch-requests plugin allows overwriting the X-REAL-IP header | Apache Software Foundation | 9.8 | 96.1% | KEV | 2022-02-11 |
| CVE-2022-23131 | Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML | Zabbix | 9.1 | 95.7% | KEV | 2022-01-13 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-290?→
CWE-290 is authentication bypass by spoofing: the authentication scheme accepts a forged identity attribute.
What are examples of spoofable authentication factors?→
MITRE's child entries cover source IP addresses (CWE-291) and reverse DNS results (CWE-350), both of which can be falsified.
How many exploited vulnerabilities are classified as CWE-290?→
This database lists 5 CVE records mapped to CWE-290 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2023-50224, CVE-2024-54085, CVE-2024-4358.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.