This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
578 vulnerabilities with CWE-290
CVE-2021-21215
MEDIUM
Google Chrome < 90.0.4430.72 - Authentication Bypass by Spoofing via Autofill
CVSS 6.5
CVE-2021-0232
HIGH
Juniper Paragon Active Assurance Control Center < 2.35.6 - Improper Access Control
CVSS 7.4
CVE-2021-21492
MEDIUM
SAP NetWeaver Application Server Java - Content Spoofing via Logon Group URL Validation
CVSS 4.3
CVE-2021-22890
LOW
curl/libcurl 7.63.0-7.75.0 - HTTPS Proxy MITM via TLS Session Tickets
CVSS 3.7
CVE-2021-23984
MEDIUM
Firefox < 87.0 and Firefox ESR < 78.9 - Authentication Bypass by Spoofing via Popup Window
CVSS 6.5
CVE-2021-21310
MEDIUM
next-auth < 3.3.0 - Authentication Bypass via Prisma Adapter Email Token Verification
CVSS 6.1
CVE-2021-21134
MEDIUM
Google Chrome < 88.0.4324.96 - Security UI Spoofing via Page Info
CVSS 6.5
CVE-2021-1677
MEDIUM
Azure Kubernetes Service - Authentication Bypass via Azure Active Directory Pod Identity Spoofing
CVSS 5.5
CVE-2020-37056
CRITICAL
Crystal Shard http-protection 0.2.0 - SSRF
CVSS 9.8
CVE-2020-6158
MEDIUM
Opera Mini for Android <52.2 - CSRF
CVSS 4.7
CVE-2020-22660
HIGH
Ruckus APs and SmartZone Controllers - Secure Boot Bypass via Backup Image Fallback
CVSS 7.5
CVE-2020-19003
MEDIUM
Gate One 1.2.0 - Authentication Bypass via Origin Verification Spoofing
CVSS 5.3
CVE-2020-27970
MEDIUM
Yandex Browser < 20.10.0 - Address Bar Spoofing
CVSS 5.3
CVE-2020-7388
CRITICAL
Sage X3 AdxAdmin < 93.2.53 - Unauthenticated Remote Command Execution via AdxDSrv.exe Authentication Bypass
CVSS 10.0
CVE-2020-13529
MEDIUM
systemd - Denial of Service via DHCP FORCERENEW Packet Spoofing
CVSS 6.1
CVE-2020-36128
HIGH
PAXSTORE < 7.0.8_20200511171508 - Authentication Bypass via X-Terminal-Token Spoofing
CVSS 8.2
CVE-2020-22001
CRITICAL
HomeAutomation 3.3.2 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
CVE-2020-17516
HIGH
Apache Cassandra <3.11.10 - Info Disclosure
CVSS 7.5
CVE-2020-25686
LOW
dnsmasq < 2.83 - DNS Cache Poisoning via Birthday Attack
CVSS 3.7
CVE-2020-27276
MEDIUM
SOOIL Developments Co Ltd DiabecareRS - Auth Bypass
CVSS 5.7
CVE-2020-26276
CRITICAL
Fleet < 3.5.1 - SAML Authentication Bypass via XML Parsing Mutation
CVSS 10.0
CVE-2020-28856
HIGH
OpenAsset Digital Asset Management <= 12.0.19 - Authentication Bypass via X-Forwarded-For IP Spoofing
CVSS 7.5
CVE-2020-26254
HIGH
omniauth-apple <1.0.1 - Info Disclosure
CVSS 7.7
CVE-2020-4864
MEDIUM
IBM Resilient SOAR V38.0 - Authentication Bypass by Spoofing via Spoofed Source IP Address
CVSS 4.3
CVE-2020-24375
MEDIUM
Freebox Server < 4.2.3 - Authentication Bypass via DNS Rebinding
CVSS 6.5
Details
Vulnerabilities
578