This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
637 vulnerabilities with CWE-290
CVE-2020-22001
CRITICAL
HomeAutomation 3.3.2 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 9.8
CVE-2020-17516
HIGH
Apache Cassandra <3.11.10 - Info Disclosure
CVSS 7.5
CVE-2020-25686
LOW
dnsmasq < 2.83 - DNS Cache Poisoning via Birthday Attack
CVSS 3.7
CVE-2020-27276
MEDIUM
SOOIL Developments Co Ltd DiabecareRS - Auth Bypass
CVSS 5.7
CVE-2020-26276
CRITICAL
Fleet < 3.5.1 - SAML Authentication Bypass via XML Parsing Mutation
CVSS 10.0
CVE-2020-28856
HIGH
OpenAsset Digital Asset Management <= 12.0.19 - Authentication Bypass via X-Forwarded-For IP Spoofing
CVSS 7.5
CVE-2020-26254
HIGH
omniauth-apple <1.0.1 - Info Disclosure
CVSS 7.7
CVE-2020-4864
MEDIUM
IBM Resilient SOAR V38.0 - Authentication Bypass by Spoofing via Spoofed Source IP Address
CVSS 4.3
CVE-2020-24375
MEDIUM
Freebox Server < 4.2.3 - Authentication Bypass via DNS Rebinding
CVSS 6.5
CVE-2020-7327
MEDIUM
McAfee MVISION Endpoint Detection and Response Client < 3.2.0 - Authentication Bypass via Windows Service Manipulation
CVSS 6.0
CVE-2020-7326
MEDIUM
McAfee Active Response < 2.4.4 - Authentication Bypass via Windows Service Manipulation
CVSS 6.0
CVE-2020-16250
HIGH
HashiCorp Vault 0.7.1-1.2.4 - Authentication Bypass via AWS IAM Auth Method
CVSS 8.2
CVE-2020-5415
CRITICAL
Concourse <6.3.1, 6.4.1 - Info Disclosure
CVSS 10.0
CVE-2020-2033
MEDIUM
GlobalProtect 5.0.0-5.0.9 - Authentication Bypass via ARP Spoofing
CVSS 5.3
CVE-2020-1331
MEDIUM
System Center Operations Manager - Spoofing via Web Request
CVSS 5.4
CVE-2020-1329
MEDIUM
Microsoft Bing Search for Android - Spoofing via HTML Content
CVSS 6.5
CVE-2020-10136
MEDIUM
Cisco NX-OS - Authentication Bypass by Spoofing via IP-in-IP Packet Handling
CVSS 5.3
CVE-2020-10135
MEDIUM
Bluetooth BR/EDR Core Specification <5.2 - Auth Bypass
CVSS 5.4
CVE-2020-2002
HIGH
PAN-OS 7.1.0-7.1.25 - Authentication Bypass via Kerberos KDC Spoofing
CVSS 8.1
CVE-2020-4421
MEDIUM
IBM WebSphere Application Liberty 19.0.0.5-20.0.0.4 - Authenticated Identity Spoofing via OpenID Connect
CVSS 5.4
CVE-2020-11015
HIGH
thinx-device-api <2.5.0 - Info Disclosure
CVSS 7.5
CVE-2020-12272
MEDIUM
OpenDMARC < 1.3.2 - Authentication Bypass by Spoofing via SPF/DKIM Parsing
CVSS 5.3
CVE-2020-4290
MEDIUM
IBM Security Information Queue 1.0.0-1.0.5 - Authenticated Configuration Owner Spoofing
CVSS 5.4
CVE-2020-6810
MEDIUM
Firefox < 74.0 - Authentication Bypass by Spoofing via Fullscreen Mode Popup
CVSS 4.3
CVE-2020-6808
MEDIUM
Firefox < 74.0 - Authentication Bypass by Spoofing via JavaScript URL Evaluation
CVSS 6.5
Details
Vulnerabilities
637