CWE · MITRE source
CWE-290Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Last updated: 21 August 2026 00:24 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 15 mapping(s) from 5 framework(s): CAPEC 10 (partial) · ATT&CK 2 (partial) · STIG oracle linux 8 1 (mostly) · STIG rhel 7 1 (mostly) · STIG rhel 8 1 (mostly)
OWASP Top 10 for Web (2025)
This weakness contributes to A07:2025 Authentication Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 3 hardening rules · 3 OS baselines
V6.4.3V10.4.16V10.5.1V11.4.3
NIST 800-53 r5 controls that address this weakness (11)AI-assisted
Showing the 8 most specific. Generic controls that address many weakness types are collapsed below.
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-11 | Trusted Path | SC | Isolated trusted path ensures the user interacts only with genuine system components, preventing spoofing of authentication interfaces or prompts. |
SC-20 | Secure Name/Address Resolution Service (Authoritative Source) | SC | Directly counters DNS response spoofing by requiring cryptographic origin authentication artifacts from the authoritative source. |
SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | SC | Directly counters DNS response spoofing by requiring cryptographic origin authentication before trusting resolved names/addresses. |
IA-12 | Identity Proofing | IA | Requiring verifiable identity evidence at appropriate assurance levels makes it substantially harder for attackers to successfully spoof or impersonate users to obtain accounts. |
IA-3 | Device Identification and Authentication | IA | Unique device authentication makes successful spoofing of device identity substantially more difficult to achieve. |
IA-8 | Identification and Authentication (Non-organizational Users) | IA | Unique identification of non-organizational users reduces the feasibility of authentication bypass by spoofing. |
AC-9 | Previous Logon Notification | AC | Reveals spoofed logon attempts through unexpected previous logon timestamps upon legitimate login. |
AT-2 | Literacy Training and Awareness | AT | Training specifically addresses recognizing spoofed communications and phishing that enable authentication bypass. |
Show 3 more broadly-applicable controls
SC-23 | Session Authenticity | SC | Requires cryptographic or protocol-level verification that blocks spoofed session establishment or continuation. |
SC-40 | Wireless Link Protection | SC | Signal-parameter protections (e.g., cryptographic authentication, anti-spoofing) directly counter spoofing-based authentication bypass. |
IA-9 | Service Identification and Authentication | IA | Unique identification and authentication of services before communications makes spoofing of service identities substantially harder. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2022-24112 KEV UPD | 9.9 | 9.8 | 0.9600 | 2022-02-11 |
CVE-2024-4358 KEV UPD | 9.9 | 9.8 | 0.9748 | 2024-05-29 |
CVE-2024-54085 KEV UPD | 9.9 | 9.8 | 0.6083 | 2025-03-11 |
CVE-2020-7388 UPD | 9.8 | 10.0 | 0.6944 | 2021-07-22 |
CVE-2022-23131 KEV UPD | 9.5 | 9.1 | 0.9568 | 2022-01-13 |
CVE-2021-34646 UPD | 9.4 | 9.8 | 0.5087 | 2021-08-30 |
CVE-2025-49002 UPD | 9.2 | 9.8 | 0.4502 | 2025-06-03 |
CVE-2018-7842 UPD | 9.0 | 9.8 | 0.3504 | 2019-05-22 |
CVE-2021-29441 UPD | 8.7 | 8.6 | 0.6963 | 2021-04-27 |
CVE-2023-30803 UPD | 8.5 | 9.8 | 0.1821 | 2023-10-10 |
CVE-2019-1234 UPD | 8.4 | 7.5 | 0.7374 | 2019-11-12 |
CVE-2018-5353 UPD | 8.2 | 9.8 | 0.1106 | 2020-09-30 |
CVE-2022-3180 UPD | 8.2 | 9.8 | 0.0921 | 2025-02-11 |
CVE-2009-1048 UPD | 8.0 | 9.8 | 0.0637 | 2009-08-14 |
CVE-2019-16871 UPD | 8.0 | 9.8 | 0.0530 | 2019-12-19 |
CVE-2017-14375 UPD | 7.9 | 9.8 | 0.0477 | 2017-11-01 |
CVE-2025-32966 UPD | 7.9 | 9.8 | 0.0440 | 2025-04-23 |
CVE-2018-15715 UPD | 7.8 | 9.8 | 0.0349 | 2018-11-30 |
CVE-2020-26276 UPD | 7.8 | 10.0 | 0.0217 | 2020-12-17 |
CVE-2020-22001 UPD | 7.8 | 9.8 | 0.0341 | 2021-04-27 |
CVE-2025-69258 UPD | 7.8 | 9.8 | 0.0353 | 2026-01-08 |
CVE-2017-14003 UPD | 7.7 | 9.8 | 0.0260 | 2017-10-11 |
CVE-2019-16378 UPD | 7.7 | 9.8 | 0.0246 | 2019-09-17 |
CVE-2019-18259 UPD | 7.7 | 9.8 | 0.0211 | 2019-12-16 |
CVE-2019-20790 UPD | 7.7 | 9.8 | 0.0255 | 2020-04-27 |