CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2020-10807 MEDIUM
Caldera < 2.6.5 - Authentication Bypass via HTTP Host Header Spoofing
CVSS 5.3
CVE-2019-25023 MEDIUM
Scytl sVote 2.1 - IP Address Spoofing via X-Forwarded-For Header
CVSS 6.5
CVE-2019-18991 MEDIUM
Atheros AR9132/AR9283/AR9285 - Auth Bypass
CVSS 5.4
CVE-2019-18990 MEDIUM
Realtek RTL8812AR 1.21WW - Auth Bypass
CVSS 5.4
CVE-2019-18989 MEDIUM
Mediatek MT7620N 1.06 - Auth Bypass
CVSS 5.4
CVE-2019-20790 CRITICAL
OpenDMARC <= 1.3.2 and 1.4.x - Authentication Bypass via HELO/MAIL FROM Inconsistency
CVSS 9.8
CVE-2019-12131 CRITICAL
ONAP APPC and SDC 3.0.0-4.0.0 - Unauthenticated Authentication Bypass via USER_ID Header Spoofing
CVSS 9.1
CVE-2019-11189 HIGH
ONOS < 2.0.0 - Authentication Bypass via Gratuitous ARP Reply
CVSS 7.5
CVE-2019-20203 MEDIUM
Postie < 1.9.40 - Authentication Bypass via Email From Address Spoofing
CVSS 5.3
CVE-2019-16871 CRITICAL
Beckhoff TwinCAT < 3.1 - Remote Code Execution via ADS Protocol
CVSS 9.8
CVE-2019-18259 CRITICAL
Omron PLC CJ and CS Firmware - Authentication Bypass by Spoofing
CVSS 9.8
CVE-2019-16766 HIGH
wagtail-2fa < 1.3.0 - Authentication Bypass via URL Manipulation
CVSS 8.7
CVE-2019-13715 MEDIUM
Google Chrome < 78.0.3904.70 - Domain Spoofing via IDN Homographs in Omnibox
CVSS 4.3
CVE-2019-13709 MEDIUM
Google Chrome <78.0.3904.70 - Auth Bypass
CVSS 6.5
CVE-2019-13708 MEDIUM
Google Chrome < 78.0.3904.70 - Authentication Bypass by Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2019-13704 MEDIUM
Google Chrome < 78.0.3904.70 - Content Security Policy Bypass via Crafted HTML Page
CVSS 4.3
CVE-2019-13703 MEDIUM
Google Chrome <78.0.3904.70 - Info Disclosure
CVSS 4.3
CVE-2019-13701 MEDIUM
Google Chrome < 78.0.3904.70 - URL Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2019-0388 MEDIUM
SAP UI5 - Content Manipulation via Insufficient URL Validation
CVSS 5.3
CVE-2019-1234 HIGH
Azure Stack - Authentication Bypass by Spoofing via Request Validation Failure
CVSS 7.5
CVE-2019-18659 MEDIUM
Wireless Emergency Alerts Protocol - Presidential Alert Spoofing
CVSS 5.3
CVE-2019-1357 MEDIUM
Internet Explorer - Authentication Bypass via Cookie Handling
CVSS 4.3
CVE-2019-1318 MEDIUM
Windows - Authentication Bypass via TLS Non-EMS Session Spoofing
CVSS 5.9
CVE-2019-0608 MEDIUM
Internet Explorer - Spoofing via HTTP Content Parsing
CVSS 4.3
CVE-2019-15022 HIGH
Zingbox Inspector < 1.294 - ARP Spoofing Authentication Bypass
CVSS 7.5
Details
Vulnerabilities 637