CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

210 vulnerabilities with CWE-294
CVE-2023-39547 HIGH
CLUSTERPRO X <5.1 - Command Injection
CVSS 8.8
CVE-2023-45794 MEDIUM
Mendix 10<10.4.0, Mendix 7<7.23.37, Mendix 8<8.18.27, Mendix 9<9.24...
CVSS 6.8
CVE-2023-36857 MEDIUM
Baker Hughes - Bently Nevada 3500 System TDI Firmware <5.05 - Replay
CVSS 5.4
CVE-2023-41890 HIGH
Sustainsys.Saml2 <1.0.3, <2.9.2 - Info Disclosure
CVSS 7.5
CVE-2023-30909 CRITICAL
HP Oneview < 8.30.01 - Authentication Bypass
CVSS 9.8
CVE-2023-39373 HIGH
Hyundai 2017 Firmware - Authentication Bypass
CVSS 7.4
CVE-2023-20900 HIGH
VMware vSphere <8.0 - Privilege Escalation
CVSS 7.1
CVE-2023-34625 HIGH
Showmojo Mojobox Firmware - Authentication Bypass
CVSS 8.1
CVE-2023-2846 HIGH
Mitsubishi Electric Corporation MELSEC iQ-F Series - Auth Bypass
CVSS 7.5
CVE-2023-34553 MEDIUM
WAFU Keyless Smart Lock v1.0 - Code Injection
CVSS 6.5
CVE-2023-29158 MEDIUM
SUBNET PowerSYSTEM Center <2020 U10 - DoS
CVSS 6.1
CVE-2023-33621 MEDIUM
GL.iNET GL-AR750S-Ext <3.215 - Auth Bypass
CVSS 5.9
CVE-2023-31763 HIGH
AGShome Smart Alarm v1.0 - Info Disclosure
CVSS 7.5
CVE-2023-31762 HIGH
Digoo DG-HAMB Smart Home Security System v1.0 - Code Injection
CVSS 7.5
CVE-2023-31761 HIGH
Blitzwolf BW-IS22 - Code Injection
CVSS 7.5
CVE-2023-31759 HIGH
Kerui W18 Alarm System v1.0 - Code Injection
CVSS 7.5
CVE-2023-33281 MEDIUM
Nissan Sylphy Classic 2021 - Replay Attack
CVSS 6.5
CVE-2023-20123 MEDIUM
Cisco Duo - Info Disclosure
CVSS 6.3
CVE-2023-1886 HIGH
thorsten/phpmyfaq <3.1.12 - Auth Bypass
CVSS 7.3
CVE-2023-1537 CRITICAL
answerdev/answer <1.0.6 - Auth Bypass
CVSS 9.8
CVE-2023-23397 CRITICAL KEV
Microsoft Outlook - Privilege Escalation
CVSS 9.8
CVE-2023-0014 CRITICAL
SAP NetWeaver ABAP Server/ABAP Platform - Info Disclosure
CVSS 9.0
CVE-2023-0036 MEDIUM
OpenHarmony <v3.0.5 - Auth Bypass
CVSS 6.5
CVE-2023-0035 MEDIUM
OpenHarmony <v3.0.5 - Auth Bypass
CVSS 6.5
CVE-2022-46480 HIGH
Ultraloq UL3 2nd Gen Smart Lock <02.27.0012 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 210
Exploit Likelihood High