CWE-294
High likelihoodAuthentication Bypass by Capture-replay
Parent: CWE-1390 - Weak Authentication
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
219 vulnerabilities with CWE-294
CVE-2023-33281
MEDIUM
Nissan Sylphy Classic 2021 - Replay Attack
CVSS 6.5
CVE-2023-20123
MEDIUM
Cisco Duo < 2.0.1 & Duo Authentication for Windows Logon and RDP < 4.2.2 - Authentication Bypass via Session Replay
CVSS 6.3
CVE-2023-1886
HIGH
thorsten/phpmyfaq <3.1.12 - Auth Bypass
CVSS 7.3
CVE-2023-1537
CRITICAL
answerdev/answer <1.0.6 - Auth Bypass
CVSS 9.8
CVE-2023-23397
CRITICAL
KEV
Microsoft Outlook - Privilege Escalation
CVSS 9.8
CVE-2023-0014
CRITICAL
SAP NetWeaver ABAP Server/ABAP Platform - Info Disclosure
CVSS 9.0
CVE-2023-0036
MEDIUM
OpenHarmony 3.0-3.0.5 - Authentication Bypass via platform_callback_stub
CVSS 6.5
CVE-2023-0035
MEDIUM
OpenHarmony 3.0-3.0.5 - Authentication Bypass via SA Relay Attack
CVSS 6.5
CVE-2022-46480
HIGH
Ultraloq UL3 2nd Gen Smart Lock <02.27.0012 - Info Disclosure
CVSS 8.1
CVE-2022-48507
HIGH
Huawei EMUI and HarmonyOS - Authentication Bypass via Identity Verification Bypass
CVSS 7.5
CVE-2022-47930
MEDIUM
IO FinNet tss-lib <2.0.0 - Info Disclosure
CVSS 6.8
CVE-2022-45789
HIGH
Schneider-electric Ecostruxure Control Expert - Authentication Bypass
CVSS 8.1
CVE-2022-43704
MEDIUM
Sinilink XY-WFT1 WiFi Remote Thermostat <1.3.6 - Auth Bypass
CVSS 5.9
CVE-2022-38766
HIGH
Renault ZOE E-Tech Firmware - Authentication Bypass via Replay Attack
CVSS 8.1
CVE-2022-2226
MEDIUM
Thunderbird < 91.11 and < 102 - Digital Signature Replay Attack via Date Mismatch
CVSS 6.5
CVE-2022-25837
HIGH
Bluetooth Core Specification <5.3 - Unauthenticated MITM
CVSS 7.5
CVE-2022-25836
HIGH
Bluetooth Core Specification <5.3 - Auth Bypass
CVSS 7.5
CVE-2022-45914
MEDIUM
electronic_shelf_label_protocol - Unauthenticated Label Value Manipulation via 433 MHz RF Signals
CVSS 6.5
CVE-2022-44555
HIGH
HarmonyOS - Service Hijacking via DDMP/ODMF Module
CVSS 7.5
CVE-2022-44457
CRITICAL
Mendix SAML < 1.17.0 - Authentication Bypass via Capture-replay
CVSS 9.8
CVE-2022-29475
HIGH
Abode Systems iota All-In-One Security Kit 6.9X and 6.9Z - Authentication Bypass via XFINDER Capture-replay
CVSS 8.1
CVE-2022-41541
HIGH
TP-Link AX10v1 V1_211117 - Authentication Bypass via Replay Attack
CVSS 8.1
CVE-2022-2780
HIGH
Octopus Server 2021.2.994-2022.1.3180 - NTLM Relay Attack via Git Connectivity Test
CVSS 8.1
CVE-2022-42731
HIGH
django-mfa2 <2.5.1, <2.6.1 - Info Disclosure
CVSS 7.5
CVE-2022-40621
HIGH
WAVLINK Quantum D4G - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
219
Exploit Likelihood
High