CWE-294
High likelihoodAuthentication Bypass by Capture-replay
Parent: CWE-1390 - Weak Authentication
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
210 vulnerabilities with CWE-294
CVE-2024-40715
HIGH
Veeam Backup & Replication Enterprise Manager - Auth Bypass
CVSS 7.7
CVE-2024-22066
HIGH
ZTE ZXR10 ZSR V2 - Privilege Escalation
CVSS 7.5
CVE-2024-46041
HIGH
IoT Haat Smart Plug IH-IN-16A-S <5.16.1 - Auth Bypass
CVSS 8.8
CVE-2024-39081
MEDIUM
SMART TYRE CAR & BIKE <4.2.0 - SSRF
CVSS 4.2
CVE-2024-43099
HIGH
Session Hijacking - Auth Bypass
CVSS 8.8
CVE-2024-8260
MEDIUM
OPA for Windows <v0.68.0 - SMB Force-Authentication
CVSS 6.1
CVE-2024-3982
HIGH
MicroSCADA X - Session Hijacking
CVSS 8.2
CVE-2024-45244
MEDIUM
Hyperledger Fabric <3.0.0, <2.5.10 - Info Disclosure
CVSS 5.3
CVE-2024-38890
HIGH
Horizoncloud Caterease < 24.0.1.2405 - Authentication Bypass
CVSS 8.4
CVE-2024-5249
MEDIUM
Akana API Platform <2024.1.0 - Info Disclosure
CVSS 5.4
CVE-2024-38438
CRITICAL
D-Link - Auth Bypass
CVSS 9.8
CVE-2024-37016
MEDIUM
Mengshen Wireless Door Alarm M70 - Auth Bypass
CVSS 6.8
CVE-2024-38272
MEDIUM
Quick Share <1.0.1724.0 - Auth Bypass
CVSS 4.3
CVE-2024-38284
HIGH
Transmitted data - Info Disclosure
CVE-2024-34065
HIGH
Strapi <4.24.2 - Auth Bypass
CVSS 7.1
CVE-2024-4009
CRITICAL
ABB, Busch-Jaeger, FTS Display <1.00 & BCU <1.3.0.33 - Replay Attack
CVSS 9.2
CVE-2024-29851
HIGH
Veeam Backup Enterprise Manager - Info Disclosure
CVSS 7.2
CVE-2024-29850
HIGH
Veeam Backup Enterprise Manager - Privilege Escalation
CVSS 8.8
CVE-2024-29901
MEDIUM
AuthKit <0.4.2 - SSRF
CVSS 4.8
CVE-2023-50786
MEDIUM
Dradis <4.16.0 - Info Disclosure
CVSS 4.1
CVE-2023-47435
CRITICAL
hexo-theme-matery v2.0.0 - Auth Bypass
CVSS 9.8
CVE-2023-49231
CRITICAL
Stilog Visual Planning 8 - Auth Bypass
CVSS 9.8
CVE-2023-6374
MEDIUM
Mitsubishi Electric Corporation MELSEC WS Series - Auth Bypass
CVSS 5.9
CVE-2023-46892
HIGH
Meross MSH30Q <4.5.23 - Replay Attack
CVSS 8.8
CVE-2023-50128
MEDIUM
Hozard Alarm System <v1.0 - Replay Attack
CVSS 5.3
Details
Vulnerabilities
210
Exploit Likelihood
High