CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

219 vulnerabilities with CWE-294
CVE-2023-33281 MEDIUM
Nissan Sylphy Classic 2021 - Replay Attack
CVSS 6.5
CVE-2023-20123 MEDIUM
Cisco Duo < 2.0.1 & Duo Authentication for Windows Logon and RDP < 4.2.2 - Authentication Bypass via Session Replay
CVSS 6.3
CVE-2023-1886 HIGH
thorsten/phpmyfaq <3.1.12 - Auth Bypass
CVSS 7.3
CVE-2023-1537 CRITICAL
answerdev/answer <1.0.6 - Auth Bypass
CVSS 9.8
CVE-2023-23397 CRITICAL KEV
Microsoft Outlook - Privilege Escalation
CVSS 9.8
CVE-2023-0014 CRITICAL
SAP NetWeaver ABAP Server/ABAP Platform - Info Disclosure
CVSS 9.0
CVE-2023-0036 MEDIUM
OpenHarmony 3.0-3.0.5 - Authentication Bypass via platform_callback_stub
CVSS 6.5
CVE-2023-0035 MEDIUM
OpenHarmony 3.0-3.0.5 - Authentication Bypass via SA Relay Attack
CVSS 6.5
CVE-2022-46480 HIGH
Ultraloq UL3 2nd Gen Smart Lock <02.27.0012 - Info Disclosure
CVSS 8.1
CVE-2022-48507 HIGH
Huawei EMUI and HarmonyOS - Authentication Bypass via Identity Verification Bypass
CVSS 7.5
CVE-2022-47930 MEDIUM
IO FinNet tss-lib <2.0.0 - Info Disclosure
CVSS 6.8
CVE-2022-45789 HIGH
Schneider-electric Ecostruxure Control Expert - Authentication Bypass
CVSS 8.1
CVE-2022-43704 MEDIUM
Sinilink XY-WFT1 WiFi Remote Thermostat <1.3.6 - Auth Bypass
CVSS 5.9
CVE-2022-38766 HIGH
Renault ZOE E-Tech Firmware - Authentication Bypass via Replay Attack
CVSS 8.1
CVE-2022-2226 MEDIUM
Thunderbird < 91.11 and < 102 - Digital Signature Replay Attack via Date Mismatch
CVSS 6.5
CVE-2022-25837 HIGH
Bluetooth Core Specification <5.3 - Unauthenticated MITM
CVSS 7.5
CVE-2022-25836 HIGH
Bluetooth Core Specification <5.3 - Auth Bypass
CVSS 7.5
CVE-2022-45914 MEDIUM
electronic_shelf_label_protocol - Unauthenticated Label Value Manipulation via 433 MHz RF Signals
CVSS 6.5
CVE-2022-44555 HIGH
HarmonyOS - Service Hijacking via DDMP/ODMF Module
CVSS 7.5
CVE-2022-44457 CRITICAL
Mendix SAML < 1.17.0 - Authentication Bypass via Capture-replay
CVSS 9.8
CVE-2022-29475 HIGH
Abode Systems iota All-In-One Security Kit 6.9X and 6.9Z - Authentication Bypass via XFINDER Capture-replay
CVSS 8.1
CVE-2022-41541 HIGH
TP-Link AX10v1 V1_211117 - Authentication Bypass via Replay Attack
CVSS 8.1
CVE-2022-2780 HIGH
Octopus Server 2021.2.994-2022.1.3180 - NTLM Relay Attack via Git Connectivity Test
CVSS 8.1
CVE-2022-42731 HIGH
django-mfa2 <2.5.1, <2.6.1 - Info Disclosure
CVSS 7.5
CVE-2022-40621 HIGH
WAVLINK Quantum D4G - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 219
Exploit Likelihood High