CWE-290— Authentication Bypass by Spoofing
534 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-290page 2 of 11
- CVE-2019-3775HIGHCVSS 7.1EG 6.52019-03-07
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
- CVE-2019-3884MEDIUMCVSS 5.4EG 5.42019-08-01
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 a…
- CVE-2020-10135MEDIUMCVSS 5.4EG 5.42020-05-19
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthent…
- CVE-2020-10136MEDIUMCVSS 5.3EG 5.32020-06-02
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to v…
- CVE-2020-10807MEDIUMCVSS 5.3EG 5.32020-03-22
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
- CVE-2020-11015HIGHCVSS 7.5EG 7.52020-04-30
A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address may pass to create n…
- CVE-2020-12272MEDIUMCVSS 5.3EG 5.32020-04-27
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authent…
- CVE-2020-1329MEDIUMCVSS 6.5EG 6.52020-06-09
A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'.
- CVE-2020-1331MEDIUMCVSS 5.4EG 5.42020-06-09
A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'.
- CVE-2020-13529MEDIUMCVSS 6.1EG 6.12021-05-10
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FOR…
- CVE-2020-16250HIGHCVSS 8.2EG 8.22020-08-26
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
- CVE-2020-17516HIGHCVSS 7.5EG 7.52021-02-03
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or…
- CVE-2020-19003MEDIUMCVSS 5.3EG 5.32021-10-06
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
- CVE-2020-2002HIGHCVSS 8.1EG 8.12020-05-13
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticati…
- CVE-2020-2033MEDIUMCVSS 5.3EG 5.32020-06-10
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with …
- CVE-2020-22001CRITICALCVSS 9.8EG 9.82021-04-27
HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.
- CVE-2020-22660HIGHCVSS 7.5EG 7.52023-01-20
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) befo…
- CVE-2020-24375MEDIUMCVSS 6.5EG 6.52020-10-19
A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
- CVE-2020-25686LOWCVSS 3.7EG 3.72021-01-20
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstr…
- CVE-2020-26254HIGHCVSS 7.7EG 7.72020-12-08
omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. This vulnerability impacts applications using t…
- CVE-2020-26276CRITICALCVSS 10.0EG 10.02020-12-17
Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unv…
- CVE-2020-27276MEDIUMCVSS 5.7EG 5.72021-01-19
SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entities before exchangin…
- CVE-2020-27970MEDIUMCVSS 5.3EG 5.32021-09-13
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
- CVE-2020-28856HIGHCVSS 7.5EG 7.52020-12-14
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127…
- CVE-2020-36128HIGHCVSS 8.2EG 8.22021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the ter…
- CVE-2020-37056CRITICALCVSS 9.8EG 9.82026-01-30
Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-I…
- CVE-2020-4290MEDIUMCVSS 5.4EG 5.42020-04-08
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access.…
- CVE-2020-4421MEDIUMCVSS 5.4EG 5.42020-05-06
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
- CVE-2020-4864MEDIUMCVSS 4.3EG 4.32020-10-29
IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address. IBM X-Force ID: 190567.
- CVE-2020-5415CRITICALCVSS 10.0EG 10.02020-08-12
Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to …
- CVE-2020-6158MEDIUMCVSS 4.7EG 4.72025-02-21
Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to im…
- CVE-2020-6808MEDIUMCVSS 6.5EG 6.52020-03-25
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for exa…
- CVE-2020-6810MEDIUMCVSS 4.3EG 4.32020-03-25
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confu…
- CVE-2020-7326MEDIUMCVSS 6.0EG 6.02020-10-15
Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state …
- CVE-2020-7327MEDIUMCVSS 6.0EG 6.72020-10-15
Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust co…
- CVE-2020-7388CRITICALCVSS 10.0EG 10.02021-07-22
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the…
- CVE-2021-0232HIGHCVSS 7.4EG 7.42021-04-22
An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configurat…
- CVE-2021-1677MEDIUMCVSS 5.5EG 5.52021-01-12
Azure Active Directory Pod Identity Spoofing Vulnerability
- CVE-2021-20278MEDIUMCVSS 6.5EG 6.52021-05-28
An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by the underlying clust…
- CVE-2021-21134MEDIUMCVSS 6.5EG 6.52021-02-09
Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.
- CVE-2021-21215MEDIUMCVSS 6.5EG 6.52021-04-26
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
- CVE-2021-21216MEDIUMCVSS 6.5EG 6.52021-04-26
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
- CVE-2021-21310MEDIUMCVSS 6.1EG 6.12021-02-11
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction wit…
- CVE-2021-21492MEDIUMCVSS 4.3EG 4.32021-04-13
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.
- CVE-2021-22779CRITICALCVSS 9.1EG 9.12021-07-14
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, in…
- CVE-2021-22890LOWCVSS 3.7EG 3.72021-04-01
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets a…
- CVE-2021-23984MEDIUMCVSS 6.5EG 6.52021-03-31
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and atte…
- CVE-2021-25827CRITICALCVSS 9.8EG 9.82023-06-28
Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.
- CVE-2021-26418MEDIUMCVSS 4.6EG 7.12021-05-11
Microsoft SharePoint Server Spoofing Vulnerability
- CVE-2021-27853MEDIUMCVSS 4.7EG 4.72022-09-27
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
Map vulnerabilities like CWE-290 to your infrastructure
EchelonGraph correlates every CVE — across CWE-290 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →