CWE-290
627 CVEs • Abstraction: Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CVEs (627)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adselfservice Plus Jul 9, 2026 Sep 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before op...Show more |
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.. |
1Pivotal Software 1Concourse Jun 17, 2026 Aug 12, 2020 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is...Show more |
1Paloaltonetworks 1Globalprotect Jun 17, 2026 Jun 10, 2020 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area ne...Show more |
1Microsoft 1System Center Operations Manager Jun 17, 2026 Jun 9, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnera...Show more |
A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'. |
4Cisco DigiHp+1 more6Nx Os SarosTcp/ip+3 moreJun 17, 2026 Jun 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack...Show more |
2Bluetooth Opensuse2Bluetooth Core LeapJun 17, 2026 May 19, 2020 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent a...Show more |
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC)...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 May 6, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084. |
1Thinx Device Api Project 1Thinx Device Api Jun 17, 2026 Apr 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address m...Show more |
2Fedoraproject Trusteddomain2Fedora OpendmarcJun 17, 2026 Apr 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation...Show more |
3Fedoraproject Pypolicyd Spf ProjectTrusteddomain3Fedora OpendmarcPypolicyd SpfJun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field. |
1Ibm 1Security Information Queue Jun 17, 2026 Apr 8, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for u...Show more |
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this coul...Show more |
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.locatio...Show more |
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header. |
1Onap 1Open Network Automation Platform Jun 17, 2026 Mar 18, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and...Show more |
Authentication Bypass by Spoofing in org.onosproject.acl (access control) and org.onosproject.mobility (host mobility) in ONOS v2.0 and earlier allows attackers to bypass network access control via data plane packet inje...Show more |
The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message. |