CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

578 vulnerabilities with CWE-290
CVE-2020-7327 MEDIUM
McAfee MVISION Endpoint Detection and Response Client < 3.2.0 - Authentication Bypass via Windows Service Manipulation
CVSS 6.0
CVE-2020-7326 MEDIUM
McAfee Active Response < 2.4.4 - Authentication Bypass via Windows Service Manipulation
CVSS 6.0
CVE-2020-16250 HIGH
HashiCorp Vault 0.7.1-1.2.4 - Authentication Bypass via AWS IAM Auth Method
CVSS 8.2
CVE-2020-5415 CRITICAL
Concourse <6.3.1, 6.4.1 - Info Disclosure
CVSS 10.0
CVE-2020-2033 MEDIUM
GlobalProtect 5.0.0-5.0.9 - Authentication Bypass via ARP Spoofing
CVSS 5.3
CVE-2020-1331 MEDIUM
System Center Operations Manager - Spoofing via Web Request
CVSS 5.4
CVE-2020-1329 MEDIUM
Microsoft Bing Search for Android - Spoofing via HTML Content
CVSS 6.5
CVE-2020-10136 MEDIUM
Cisco NX-OS - Authentication Bypass by Spoofing via IP-in-IP Packet Handling
CVSS 5.3
CVE-2020-10135 MEDIUM
Bluetooth BR/EDR Core Specification <5.2 - Auth Bypass
CVSS 5.4
CVE-2020-2002 HIGH
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via Kerberos KDC Spoofing
CVSS 8.1
CVE-2020-4421 MEDIUM
IBM WebSphere Application Liberty 19.0.0.5-20.0.0.4 - Authenticated Identity Spoofing via OpenID Connect
CVSS 5.4
CVE-2020-11015 HIGH
thinx-device-api <2.5.0 - Info Disclosure
CVSS 7.5
CVE-2020-12272 MEDIUM
OpenDMARC < 1.3.2 - Authentication Bypass by Spoofing via SPF/DKIM Parsing
CVSS 5.3
CVE-2020-4290 MEDIUM
IBM Security Information Queue 1.0.0-1.0.5 - Authenticated Configuration Owner Spoofing
CVSS 5.4
CVE-2020-6810 MEDIUM
Firefox < 74.0 - Authentication Bypass by Spoofing via Fullscreen Mode Popup
CVSS 4.3
CVE-2020-6808 MEDIUM
Firefox < 74.0 - Authentication Bypass by Spoofing via JavaScript URL Evaluation
CVSS 6.5
CVE-2020-10807 MEDIUM
Caldera < 2.6.5 - Authentication Bypass via HTTP Host Header Spoofing
CVSS 5.3
CVE-2019-25023 MEDIUM
Scytl sVote 2.1 - IP Address Spoofing via X-Forwarded-For Header
CVSS 6.5
CVE-2019-18991 MEDIUM
Atheros AR9132/AR9283/AR9285 - Auth Bypass
CVSS 5.4
CVE-2019-18990 MEDIUM
Realtek RTL8812AR 1.21WW - Auth Bypass
CVSS 5.4
CVE-2019-18989 MEDIUM
Mediatek MT7620N 1.06 - Auth Bypass
CVSS 5.4
CVE-2019-20790 CRITICAL
OpenDMARC <= 1.3.2 and 1.4.x - Authentication Bypass via HELO/MAIL FROM Inconsistency
CVSS 9.8
CVE-2019-12131 CRITICAL
ONAP APPC and SDC 3.0.0-4.0.0 - Unauthenticated Authentication Bypass via USER_ID Header Spoofing
CVSS 9.1
CVE-2019-11189 HIGH
ONOS < 2.0.0 - Authentication Bypass via Gratuitous ARP Reply
CVSS 7.5
CVE-2019-20203 MEDIUM
Postie < 1.9.40 - Authentication Bypass via Email From Address Spoofing
CVSS 5.3
Details
Vulnerabilities 578