← Back
CWE-290

627 CVEs • Abstraction: Base

Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

JSON object

Loading...

CVEs (627)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Beckhoff
1Twincat
Jun 17, 2026
Dec 19, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
1Omron
2Plc Cj Firmware
Plc Cs Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.
1Labdigital
1Wagtail 2fa
Jun 17, 2026
Nov 29, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full ac...Show more
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.Show less
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
1Sap
1Ui
Jun 17, 2026
Nov 13, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
1Microsoft
1Azure Stack
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.
4Isc
NicNlnetlabs+1 more
4Bind
Enterprise LinuxKnot Resolver+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
Cache Poisoning issue exists in DNS Response Rate Limiting.
1Ready
1Wireless Emergency Alerts
Jun 17, 2026
Nov 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Blo...Show more
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are affected by design (e.g., use of Android versus iOS does not matter); testing in an open RF environment is, of course, contraindicated.Show less
1Microsoft
2Edge
Internet Explorer
Jun 17, 2026
Oct 10, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
1Microsoft
2Edge
Internet Explorer
Jun 17, 2026
Oct 10, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraOpendmarc+1 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin o...Show more
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.Show less
1Redhat
1Openshift
Jun 17, 2026
Aug 1, 2019
N/A· v4
5.4 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8...Show more
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.Show less
1Schneider Electric
4Modicon M340 Firmware
Modicon M580 FirmwareModicon Premium Firmware+1 more
Jun 17, 2026
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute...Show more
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.Show less