CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2021-28810 HIGH
Roon Server < 2021-05-18 - Authentication Bypass
CVSS 7.5
CVE-2021-20278 MEDIUM
Kiali < 1.31.0 - Authentication Bypass via OpenID Implicit Flow
CVSS 6.5
CVE-2021-31209 MEDIUM
Microsoft Exchange Server - Authentication Bypass by Spoofing
CVSS 6.5
CVE-2021-31195 MEDIUM
Microsoft Exchange Server - Remote Code Execution
CVSS 6.5
CVE-2021-31172 HIGH
Microsoft SharePoint Server - Authentication Bypass by Spoofing
CVSS 7.1
CVE-2021-28478 HIGH
Microsoft SharePoint Server - Authentication Bypass by Spoofing
CVSS 7.6
CVE-2021-26418 MEDIUM
Microsoft SharePoint Server - Authentication Bypass by Spoofing
CVSS 4.6
CVE-2021-29441 HIGH
Nacos < 1.4.1 - Authentication Bypass via User-Agent Spoofing
CVSS 8.6
CVE-2021-21216 MEDIUM
Google Chrome < 90.0.4430.72 - Authentication Bypass by Spoofing via Autofill Security UI
CVSS 6.5
CVE-2021-21215 MEDIUM
Google Chrome < 90.0.4430.72 - Authentication Bypass by Spoofing via Autofill
CVSS 6.5
CVE-2021-0232 HIGH
Juniper Paragon Active Assurance Control Center < 2.35.6 - Improper Access Control
CVSS 7.4
CVE-2021-21492 MEDIUM
SAP NetWeaver Application Server Java - Content Spoofing via Logon Group URL Validation
CVSS 4.3
CVE-2021-22890 LOW
curl/libcurl 7.63.0-7.75.0 - HTTPS Proxy MITM via TLS Session Tickets
CVSS 3.7
CVE-2021-23984 MEDIUM
Firefox < 87.0 and Firefox ESR < 78.9 - Authentication Bypass by Spoofing via Popup Window
CVSS 6.5
CVE-2021-21310 MEDIUM
next-auth < 3.3.0 - Authentication Bypass via Prisma Adapter Email Token Verification
CVSS 6.1
CVE-2021-21134 MEDIUM
Google Chrome < 88.0.4324.96 - Security UI Spoofing via Page Info
CVSS 6.5
CVE-2021-1677 MEDIUM
Azure Kubernetes Service - Authentication Bypass via Azure Active Directory Pod Identity Spoofing
CVSS 5.5
CVE-2020-37056 CRITICAL
Crystal Shard http-protection 0.2.0 - SSRF
CVSS 9.8
CVE-2020-6158 MEDIUM
Opera Mini for Android <52.2 - CSRF
CVSS 4.7
CVE-2020-22660 HIGH
Ruckus APs and SmartZone Controllers - Secure Boot Bypass via Backup Image Fallback
CVSS 7.5
CVE-2020-19003 MEDIUM
Gate One 1.2.0 - Authentication Bypass via Origin Verification Spoofing
CVSS 5.3
CVE-2020-27970 MEDIUM
Yandex Browser < 20.10.0 - Address Bar Spoofing
CVSS 5.3
CVE-2020-7388 CRITICAL
Sage X3 AdxAdmin < 93.2.53 - Unauthenticated Remote Command Execution via AdxDSrv.exe Authentication Bypass
CVSS 10.0
CVE-2020-13529 MEDIUM
systemd - Denial of Service via DHCP FORCERENEW Packet Spoofing
CVSS 6.1
CVE-2020-36128 HIGH
PAXSTORE < 7.0.8_20200511171508 - Authentication Bypass via X-Terminal-Token Spoofing
CVSS 8.2
Details
Vulnerabilities 637