Skip to main content

About CWE-290

The weakness can let an attacker reach resources that should require proper authentication, or assume another identity.

MITRE name
Authentication Bypass by Spoofing
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Incomplete

Mitigations

  • +Use identity verification that cannot simply be spoofed, such as credentials or certificates, instead of source IP address (CWE-291).
  • +Do not rely on reverse DNS names for security decisions (CWE-350).
  • +Where DNS names are used, perform both forward and reverse lookups to detect DNS spoofing (CWE-350).

CWE-290 Vulnerabilities

5 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2023-50224
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
TP-Link6.515.6%KEV2024-05-03
CVE-2024-54085
Redfish Authentication Bypass
AMI10.060.7%KEV2025-03-11
CVE-2024-4358
Registration Authentication Bypass Vulnerability
Progress Software Corporation9.897.5%KEV2024-05-29
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
Apache Software Foundation9.896.1%KEV2022-02-11
CVE-2022-23131
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
Zabbix9.195.7%KEV2022-01-13

Most Affected Vendors

Frequently Asked Questions

What is CWE-290?→

CWE-290 is authentication bypass by spoofing: the authentication scheme accepts a forged identity attribute.

What are examples of spoofable authentication factors?→

MITRE's child entries cover source IP addresses (CWE-291) and reverse DNS results (CWE-350), both of which can be falsified.

How many exploited vulnerabilities are classified as CWE-290?→

This database lists 5 CVE records mapped to CWE-290 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2023-50224, CVE-2024-54085, CVE-2024-4358.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.