CWE-294
High likelihoodAuthentication Bypass by Capture-replay
Parent: CWE-1390 - Weak Authentication
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
241 vulnerabilities with CWE-294
CVE-2023-50786
MEDIUM
Dradis < 4.16.0 - Net-NTLM Hash Theft via External Image Reference
CVSS 4.1
CVE-2023-47435
CRITICAL
hexo-theme-matery v2.0.0 - Auth Bypass
CVSS 9.8
CVE-2023-49231
CRITICAL
Stilog Visual Planning 8 - Auth Bypass
CVSS 9.8
CVE-2023-6374
MEDIUM
Mitsubishi Electric Corporation MELSEC WS Series - Auth Bypass
CVSS 5.9
CVE-2023-46892
HIGH
Meross MSH30Q <4.5.23 - Replay Attack
CVSS 8.8
CVE-2023-50128
MEDIUM
Hozard Alarm System <v1.0 - Replay Attack
CVSS 5.3
CVE-2023-39547
HIGH
CLUSTERPRO X <5.1 - Command Injection
CVSS 8.8
CVE-2023-45794
MEDIUM
Mendix 10<10.4.0, Mendix 7<7.23.37, Mendix 8<8.18.27, Mendix 9<9.24...
CVSS 6.8
CVE-2023-36857
MEDIUM
Baker Hughes - Bently Nevada 3500 System TDI Firmware <5.05 - Replay
CVSS 5.4
CVE-2023-41890
HIGH
Sustainsys.Saml2 <1.0.3, <2.9.2 - Info Disclosure
CVSS 7.5
CVE-2023-30909
CRITICAL
HP OneView < 8.30.01 - Authentication Bypass via API Capture-replay
CVSS 9.8
CVE-2023-39373
HIGH
Hyundai 2017 Firmware - Authentication Bypass via Capture-replay
CVSS 7.4
CVE-2023-20900
HIGH
VMware vSphere <8.0 - Privilege Escalation
CVSS 7.1
CVE-2023-34625
HIGH
ShowMojo MojoBox Digital Lockbox 1.4 - Authentication Bypass via BLE Replay Attack
CVSS 8.1
CVE-2023-2846
HIGH
Mitsubishi Electric Corporation MELSEC iQ-F Series - Auth Bypass
CVSS 7.5
CVE-2023-34553
MEDIUM
WAFU Keyless Smart Lock v1.0 - Code Injection
CVSS 6.5
CVE-2023-29158
MEDIUM
SUBNET PowerSYSTEM Center <2020 U10 - DoS
CVSS 6.1
CVE-2023-33621
MEDIUM
GL.iNET GL-AR750S-Ext <3.215 - Auth Bypass
CVSS 5.9
CVE-2023-31763
HIGH
AGShome Smart Alarm v1.0 - Info Disclosure
CVSS 7.5
CVE-2023-31762
HIGH
Digoo DG-HAMB Smart Home Security System v1.0 - Code Injection
CVSS 7.5
CVE-2023-31761
HIGH
Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 - Authentication Bypass via Code Replay Attack
CVSS 7.5
CVE-2023-31759
HIGH
Kerui W18 Alarm System v1.0 - Code Injection
CVSS 7.5
CVE-2023-33281
MEDIUM
Nissan Sylphy Classic 2021 - Replay Attack
CVSS 6.5
CVE-2023-20123
MEDIUM
Cisco Duo < 2.0.1 & Duo Authentication for Windows Logon and RDP < 4.2.2 - Authentication Bypass via Session Replay
CVSS 6.3
CVE-2023-1886
HIGH
thorsten/phpmyfaq <3.1.12 - Auth Bypass
CVSS 7.3
Details
Vulnerabilities
241
Exploit Likelihood
High