VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 24 of 34
  • CVE-2022-2368MedJul 11, 2022
    risk 0.35cvss 6.5epss 0.01

    Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.

  • CVE-2022-26910MedApr 15, 2022
    risk 0.35cvss 5.3epss 0.02

    Skype for Business and Lync Spoofing Vulnerability

  • CVE-2020-19003MedOct 6, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.

  • CVE-2020-27970MedSep 13, 2021
    risk 0.35cvss 5.3epss 0.01

    Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar

  • CVE-2021-32076MedAug 26, 2021
    risk 0.35cvss 5.3epss 0.01

    Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by…

  • CVE-2021-20278MedMay 28, 2021
    risk 0.35cvss 6.5epss 0.01

    An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by the underlying cluster. When OpenID `implicit flow` is used…

  • CVE-2019-18991MedSep 30, 2020
    risk 0.35cvss 5.4epss 0.00

    A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If…

  • CVE-2019-18990MedSep 30, 2020
    risk 0.35cvss 5.4epss 0.01

    A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the…

  • CVE-2019-18989MedSep 30, 2020
    risk 0.35cvss 5.4epss 0.01

    A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an…

  • CVE-2020-2033MedJun 10, 2020
    risk 0.35cvss 5.3epss 0.01

    When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to…

  • CVE-2020-1331MedJun 9, 2020
    risk 0.35cvss 5.4epss 0.01

    A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'.

  • CVE-2020-10135MedMay 19, 2020
    risk 0.35cvss 5.4epss 0.02

    Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could…

  • CVE-2020-4421MedMay 6, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.

  • CVE-2020-12272MedApr 27, 2020
    risk 0.35cvss 5.3epss 0.02

    OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the…

  • CVE-2020-4290MedApr 8, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.

  • CVE-2019-20203MedJan 2, 2020
    risk 0.35cvss 5.3epss 0.02

    The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.

  • CVE-2019-0388MedNov 13, 2019
    risk 0.35cvss 5.3epss 0.01

    SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.

  • CVE-2019-18659MedNov 2, 2019
    risk 0.35cvss 5.3epss 0.01

    The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated…

  • CVE-2019-3884MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

  • CVE-2018-3829MedSep 19, 2018
    risk 0.35cvss 5.3epss 0.01

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an…