CWE-290
690 CVEs • Abstraction: Base
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CVEs (690)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Realtek 4Rtl8192er Firmware Rtl8196d FirmwareRtl8812ar Firmware+1 moreJun 17, 2026 Sep 30, 2020 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected...Show more |
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the net...Show more |
The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authentic...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Jul 9, 2026 Sep 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before op...Show more |
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.. |
1Pivotal Software 1Concourse Jun 17, 2026 Aug 12, 2020 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is...Show more |
1Paloaltonetworks 1Globalprotect Jun 17, 2026 Jun 10, 2020 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area ne...Show more |
1Microsoft 1System Center Operations Manager Jun 17, 2026 Jun 9, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnera...Show more |
A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'. |
4Cisco DigiHp+1 more6Nx Os SarosTcp/ip+3 moreJun 17, 2026 Jun 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack...Show more |
2Bluetooth Opensuse2Bluetooth Core LeapJun 17, 2026 May 19, 2020 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent a...Show more |
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC)...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 May 6, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084. |
1Thinx Device Api Project 1Thinx Device Api Jun 17, 2026 Apr 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address m...Show more |
2Fedoraproject Trusteddomain2Fedora OpendmarcJun 17, 2026 Apr 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation...Show more |
3Fedoraproject Pypolicyd Spf ProjectTrusteddomain3Fedora OpendmarcPypolicyd SpfJun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field. |
1Ibm 1Security Information Queue Jun 17, 2026 Apr 8, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for u...Show more |
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this coul...Show more |
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.locatio...Show more |
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header. |