CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

210 vulnerabilities with CWE-294
CVE-2022-48507 HIGH
Storage Module - Info Disclosure
CVSS 7.5
CVE-2022-47930 MEDIUM
IO FinNet tss-lib <2.0.0 - Info Disclosure
CVSS 6.8
CVE-2022-45789 HIGH
Schneider-electric Ecostruxure Control Expert - Authentication Bypass
CVSS 8.1
CVE-2022-43704 MEDIUM
Sinilink XY-WFT1 WiFi Remote Thermostat <1.3.6 - Auth Bypass
CVSS 5.9
CVE-2022-38766 HIGH
Renault ZOE 2021 - Replay Attack
CVSS 8.1
CVE-2022-2226 MEDIUM
Thunderbird - Info Disclosure
CVSS 6.5
CVE-2022-25837 HIGH
Bluetooth Core Specification <5.3 - Unauthenticated MITM
CVSS 7.5
CVE-2022-25836 HIGH
Bluetooth Core Specification <5.3 - Auth Bypass
CVSS 7.5
CVE-2022-45914 MEDIUM
ETAG-2130-V4.3 - Info Disclosure
CVSS 6.5
CVE-2022-44555 HIGH
DDMP/ODMF - DoS
CVSS 7.5
CVE-2022-44457 CRITICAL
Mendix SAML - Info Disclosure
CVSS 9.8
CVE-2022-29475 HIGH
Goabode Iota All-in-one Security Kit Firmware - Information Disclosure
CVSS 8.1
CVE-2022-41541 HIGH
TP-Link AX10v1 - Open Redirect
CVSS 8.1
CVE-2022-2780 HIGH
Octopus Server - SSRF
CVSS 8.1
CVE-2022-42731 HIGH
django-mfa2 <2.5.1, <2.6.1 - Info Disclosure
CVSS 7.5
CVE-2022-40621 HIGH
WAVLINK Quantum D4G - Info Disclosure
CVSS 7.5
CVE-2022-37011 CRITICAL
Mendix SAML <1.17.0, <2.3.0, <3.3.0 - Auth Bypass
CVSS 9.8
CVE-2022-36089 HIGH
KubeVela <1.4.11, <1.5.4 - Auth Bypass
CVSS 8.2
CVE-2022-37418 MEDIUM
Nissan-Kia-Hyundai <2017 - RCE
CVSS 6.4
CVE-2022-37305 MEDIUM
Honda - Privilege Escalation
CVSS 6.4
CVE-2022-36945 MEDIUM
Mazda - RCE
CVSS 6.4
CVE-2022-31158 HIGH
LTI 1.3 Tool Library <5.0 - Info Disclosure
CVSS 7.5
CVE-2022-29593 MEDIUM
Dingtian DT-R002 - RCE
CVSS 5.9
CVE-2022-33971 HIGH
OMRON NX7/NX1/NJ - Auth Bypass
CVSS 7.5
CVE-2022-33208 HIGH
Machine automation controller - Auth Bypass
CVSS 8.1
Details
Vulnerabilities 210
Exploit Likelihood High