CWE
Home > CWE List > CWE-290 Individual Dictionary Definition (Draft 9)   View the CWE List

Weaknesses in this attack-focused category are caused by improperly implemented authentication schemes that are subject to spoofing attacks. Resultant vuln from insufficient verification. 1000 Weakness ChildOf 592 Authentication bypass by spoofing 21 22 94 60 59 (CWE-290)

CWE-290 Individual Dictionary Definition (Draft 9)

Authentication Bypass by Spoofing
Weakness ID
Status: Incomplete

290 (Weakness Base)

Description

Summary

Weaknesses in this attack-focused category are caused by improperly implemented authentication schemes that are subject to spoofing attacks.

Context Notes

Resultant vuln from insufficient verification.

Relationships
NatureTypeIDName
ChildOfWeakness ClassWeakness ClassWeakness Class592Authentication Bypass Issues
PeerOfWeakness VariantWeakness VariantWeakness Variant247Reliance on DNS Lookups in a Security Decision
ParentOfWeakness VariantWeakness VariantWeakness Variant292Trusting Self-reported DNS Name
ParentOfWeakness VariantWeakness VariantWeakness Variant293Using Referer Field for Authentication
CanAlsoBeWeakness BaseWeakness BaseWeakness Base358Improperly Implemented Security Check for Standard
PeerOfWeakness BaseWeakness BaseWeakness Base602Design Principle Violation: Client-Side Enforcement of Server-Side Security
ParentOfCompound Element: CompositeCompound Element: Composite291Trusting Self-reported IP Address
Source Taxonomies

PLOVER - Authentication bypass by spoofing

Related Attack Patterns
CAPEC-IDAttack Pattern Name
21Exploitation of Session Variables, Resource IDs and other Trusted Credentials
22Exploiting Trust in Client (aka Make the Client Invisible)
94Man in the Middle Attack
60Reusing Session IDs (aka Session Replay)
59Session Credential Falsification through Prediction
Page Last Updated: April 23, 2008