CWE-290
Authentication Bypass by Spoofing
Description
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94
CVEs mapped to this weakness (748)
page 27 of 38| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30058 | Med | 0.35 | 5.4 | 0.00 | Jun 13, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-21494 | Med | 0.35 | 5.4 | 0.01 | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This… | ||
| CVE-2022-33991 | Med | 0.35 | 5.3 | 0.01 | Aug 15, 2022 | dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers. | ||
| CVE-2022-35629 | Med | 0.35 | 5.4 | 0.00 | Jul 29, 2022 | Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2. | ||
| CVE-2022-2368 | Med | 0.35 | 6.5 | 0.01 | Jul 11, 2022 | Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. | ||
| CVE-2022-26910 | Med | 0.35 | 5.3 | 0.02 | Apr 15, 2022 | Skype for Business and Lync Spoofing Vulnerability | ||
| CVE-2020-19003 | Med | 0.35 | 5.3 | 0.01 | Oct 6, 2021 | An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list. | ||
| CVE-2020-27970 | Med | 0.35 | 5.3 | 0.01 | Sep 13, 2021 | Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar | ||
| CVE-2021-32076 | Med | 0.35 | 5.3 | 0.01 | Aug 26, 2021 | Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by… | ||
| CVE-2021-20278 | Med | 0.35 | 6.5 | 0.01 | May 28, 2021 | An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by the underlying cluster. When OpenID `implicit flow` is used… | ||
| CVE-2019-18991 | Med | 0.35 | 5.4 | 0.00 | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If… | ||
| CVE-2019-18990 | Med | 0.35 | 5.4 | 0.01 | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the… | ||
| CVE-2019-18989 | Med | 0.35 | 5.4 | 0.01 | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an… | ||
| CVE-2020-2033 | Med | 0.35 | 5.3 | 0.01 | Jun 10, 2020 | When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to… | ||
| CVE-2020-1331 | Med | 0.35 | 5.4 | 0.01 | Jun 9, 2020 | A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'. | ||
| CVE-2020-10135 | Med | 0.35 | 5.4 | 0.02 | May 19, 2020 | Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could… | ||
| CVE-2020-4421 | Med | 0.35 | 5.4 | 0.01 | May 6, 2020 | IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084. | ||
| CVE-2020-12272 | Med | 0.35 | 5.3 | 0.02 | Apr 27, 2020 | OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the… | ||
| CVE-2020-4290 | Med | 0.35 | 5.4 | 0.01 | Apr 8, 2020 | IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333. | ||
| CVE-2019-20203 | Med | 0.35 | 5.3 | 0.02 | Jan 2, 2020 | The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message. |
- risk 0.35cvss 5.4epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.35cvss 5.4epss 0.01
All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This…
- risk 0.35cvss 5.3epss 0.01
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
- risk 0.35cvss 5.4epss 0.00
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2.
- risk 0.35cvss 6.5epss 0.01
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
- risk 0.35cvss 5.3epss 0.02
Skype for Business and Lync Spoofing Vulnerability
- risk 0.35cvss 5.3epss 0.01
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
- risk 0.35cvss 5.3epss 0.01
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
- risk 0.35cvss 5.3epss 0.01
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by…
- risk 0.35cvss 6.5epss 0.01
An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by the underlying cluster. When OpenID `implicit flow` is used…
- risk 0.35cvss 5.4epss 0.00
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If…
- risk 0.35cvss 5.4epss 0.01
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the…
- risk 0.35cvss 5.4epss 0.01
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an…
- risk 0.35cvss 5.3epss 0.01
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to…
- risk 0.35cvss 5.4epss 0.01
A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'.
- risk 0.35cvss 5.4epss 0.02
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could…
- risk 0.35cvss 5.4epss 0.01
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
- risk 0.35cvss 5.3epss 0.02
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the…
- risk 0.35cvss 5.4epss 0.01
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.
- risk 0.35cvss 5.3epss 0.02
The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.