CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2020-22001 CRITICAL
HomeAutomation 3.3.2 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
CVE-2020-17516 HIGH
Apache Cassandra <3.11.10 - Info Disclosure
CVSS 7.5
CVE-2020-25686 LOW
dnsmasq < 2.83 - DNS Cache Poisoning via Birthday Attack
CVSS 3.7
CVE-2020-27276 MEDIUM
SOOIL Developments Co Ltd DiabecareRS - Auth Bypass
CVSS 5.7
CVE-2020-26276 CRITICAL
Fleet < 3.5.1 - SAML Authentication Bypass via XML Parsing Mutation
CVSS 10.0
CVE-2020-28856 HIGH
OpenAsset Digital Asset Management <= 12.0.19 - Authentication Bypass via X-Forwarded-For IP Spoofing
CVSS 7.5
CVE-2020-26254 HIGH
omniauth-apple <1.0.1 - Info Disclosure
CVSS 7.7
CVE-2020-4864 MEDIUM
IBM Resilient SOAR V38.0 - Authentication Bypass by Spoofing via Spoofed Source IP Address
CVSS 4.3
CVE-2020-24375 MEDIUM
Freebox Server < 4.2.3 - Authentication Bypass via DNS Rebinding
CVSS 6.5
CVE-2020-7327 MEDIUM
McAfee MVISION Endpoint Detection and Response Client < 3.2.0 - Authentication Bypass via Windows Service Manipulation
CVSS 6.0
CVE-2020-7326 MEDIUM
McAfee Active Response < 2.4.4 - Authentication Bypass via Windows Service Manipulation
CVSS 6.0
CVE-2020-16250 HIGH
HashiCorp Vault 0.7.1-1.2.4 - Authentication Bypass via AWS IAM Auth Method
CVSS 8.2
CVE-2020-5415 CRITICAL
Concourse <6.3.1, 6.4.1 - Info Disclosure
CVSS 10.0
CVE-2020-2033 MEDIUM
GlobalProtect 5.0.0-5.0.9 - Authentication Bypass via ARP Spoofing
CVSS 5.3
CVE-2020-1331 MEDIUM
System Center Operations Manager - Spoofing via Web Request
CVSS 5.4
CVE-2020-1329 MEDIUM
Microsoft Bing Search for Android - Spoofing via HTML Content
CVSS 6.5
CVE-2020-10136 MEDIUM
Cisco NX-OS - Authentication Bypass by Spoofing via IP-in-IP Packet Handling
CVSS 5.3
CVE-2020-10135 MEDIUM
Bluetooth BR/EDR Core Specification <5.2 - Auth Bypass
CVSS 5.4
CVE-2020-2002 HIGH
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via Kerberos KDC Spoofing
CVSS 8.1
CVE-2020-4421 MEDIUM
IBM WebSphere Application Liberty 19.0.0.5-20.0.0.4 - Authenticated Identity Spoofing via OpenID Connect
CVSS 5.4
CVE-2020-11015 HIGH
thinx-device-api <2.5.0 - Info Disclosure
CVSS 7.5
CVE-2020-12272 MEDIUM
OpenDMARC < 1.3.2 - Authentication Bypass by Spoofing via SPF/DKIM Parsing
CVSS 5.3
CVE-2020-4290 MEDIUM
IBM Security Information Queue 1.0.0-1.0.5 - Authenticated Configuration Owner Spoofing
CVSS 5.4
CVE-2020-6810 MEDIUM
Firefox < 74.0 - Authentication Bypass by Spoofing via Fullscreen Mode Popup
CVSS 4.3
CVE-2020-6808 MEDIUM
Firefox < 74.0 - Authentication Bypass by Spoofing via JavaScript URL Evaluation
CVSS 6.5
Details
Vulnerabilities 637