CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

241 vulnerabilities with CWE-294
CVE-2024-12137 HIGH
Elfatek Elektronics ANKA JPD-00028 - Auth Bypass
CVSS 7.6
CVE-2024-12839 HIGH
CGFIDO < 1.2.1 - Authentication Bypass via Device Signature Replay
CVSS 8.8
CVE-2024-52534 MEDIUM
Dell ECS < 3.8.1.3 - Authentication Bypass by Capture-replay
CVSS 5.4
CVE-2024-49595 HIGH
Dell Wyse Management Suite <4.4 - Auth Bypass
CVSS 7.6
CVE-2024-36250 LOW
Mattermost <9.11.3-9.5.11 - Info Disclosure
CVSS 3.1
CVE-2024-40715 HIGH
Veeam Backup & Replication Enterprise Manager - Auth Bypass
CVSS 7.7
CVE-2024-22066 HIGH
ZTE ZXR10 ZSR V2 - Privilege Escalation
CVSS 7.5
CVE-2024-46041 HIGH
IoT Haat Smart Plug IH-IN-16A-S <5.16.1 - Auth Bypass
CVSS 8.8
CVE-2024-39081 MEDIUM
SMART TYRE CAR & BIKE <4.2.0 - SSRF
CVSS 4.2
CVE-2024-43099 HIGH
DirectLogic H2-DM1E < 2.8.0 - Session Hijacking via Session Key Capture
CVSS 8.8
CVE-2024-8260 MEDIUM
OPA for Windows <v0.68.0 - SMB Force-Authentication
CVSS 6.1
CVE-2024-3982 HIGH
MicroSCADA X SYS600 10.0-10.6 - Session Hijacking via Session Logging
CVSS 8.2
CVE-2024-45244 MEDIUM
Hyperledger Fabric <3.0.0, <2.5.10 - Info Disclosure
CVSS 5.3
CVE-2024-38890 HIGH
Caterease 16.0.1.1663-24.0.1.2405 - Authentication Bypass by Capture-replay
CVSS 8.4
CVE-2024-5249 MEDIUM
Akana API Platform <2024.1.0 - Info Disclosure
CVSS 5.4
CVE-2024-38438 CRITICAL
D-Link - Auth Bypass
CVSS 9.8
CVE-2024-37016 MEDIUM
Mengshen Wireless Door Alarm M70 - Auth Bypass
CVSS 6.8
CVE-2024-38272 MEDIUM
Quick Share <1.0.1724.0 - Auth Bypass
CVSS 4.3
CVE-2024-38284 HIGH
Motorola Solutions Vigilant Fixed LPR Coms Box < 3.1.171.9 - Authentication Bypass via Replay Attack
CVE-2024-34065 HIGH
Strapi < 4.24.2 - Unauthenticated Authentication Bypass via Open Redirect and Session Token Exposure
CVSS 7.1
CVE-2024-4009 CRITICAL
ABB, Busch-Jaeger, FTS Display <1.00 & BCU <1.3.0.33 - Replay Attack
CVSS 9.2
CVE-2024-29851 HIGH
Veeam Backup Enterprise Manager - Info Disclosure
CVSS 7.2
CVE-2024-29850 HIGH
Veeam Backup Enterprise Manager - Privilege Escalation
CVSS 8.8
CVE-2024-29901 MEDIUM
AuthKit <0.4.2 - Expired Session Reuse via x-workos-session Header
CVSS 4.8
CVE-2023-33854 MEDIUM
IBM Db2 on Cloud Pak for Data - Client-Side Validation Bypass
CVSS 5.3
Details
Vulnerabilities 241
Exploit Likelihood High