CWE-294
High likelihoodAuthentication Bypass by Capture-replay
Parent: CWE-1390 - Weak Authentication
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
219 vulnerabilities with CWE-294
CVE-2022-37011
CRITICAL
Mendix SAML <1.17.0, <2.3.0, <3.3.0 - Auth Bypass
CVSS 9.8
CVE-2022-36089
HIGH
KubeVela <1.4.11, <1.5.4 - Auth Bypass
CVSS 8.2
CVE-2022-37418
MEDIUM
Nissan, Kia, and Hyundai Firmware < 2017 - Authentication Bypass via RollBack Replay Attack
CVSS 6.4
CVE-2022-37305
MEDIUM
Honda Firmware < 2018 - Authentication Bypass via RollBack Replay Attack
CVSS 6.4
CVE-2022-36945
MEDIUM
Mazda Vehicles Through 2020 - Remote Unlock via RollBack Key-Fob Replay
CVSS 6.4
CVE-2022-31158
HIGH
LTI 1.3 Tool Library <5.0 - Info Disclosure
CVSS 7.5
CVE-2022-29593
MEDIUM
Dingtian DT-R002 3.1.276A - Unauthenticated Authentication Bypass via HTTP Request Replay
CVSS 5.9
CVE-2022-33971
HIGH
OMRON NX7/NX1/NJ Series Firmware < 1.28/1.48 - Authentication Bypass by Capture-replay
CVSS 7.5
CVE-2022-33208
HIGH
Machine automation controller - Auth Bypass
CVSS 8.1
CVE-2022-30467
MEDIUM
Joyebike Wolf 2022 Firmware - Denial of Service via RF Key Fob Request Jamming
CVSS 6.8
CVE-2022-31277
HIGH
Xiaomi Lamp 1 <v2.0.4_0066 - Open Redirect
CVSS 8.8
CVE-2022-30466
MEDIUM
joybike Wolf Firmware - Authentication Bypass via Capture-replay
CVSS 6.5
CVE-2022-31265
HIGH
Wargaming World of Warships <0.11.4 - RCE
CVSS 8.8
CVE-2022-29334
CRITICAL
H v1.0 - Auth Bypass
CVSS 9.8
CVE-2022-29878
HIGH
SICAM T < V3.0 - Info Disclosure
CVSS 7.5
CVE-2022-25159
HIGH
Mitsubishielectric Fx5uc Firmware - Authentication Bypass
CVSS 8.1
CVE-2022-22936
HIGH
SaltStack Salt <3002.8-3004.1 - Privilege Escalation
CVSS 8.8
CVE-2022-27254
MEDIUM
Honda Civic 2018 Firmware - Authentication Bypass via RF Signal Replay Attack
CVSS 5.3
CVE-2022-22806
CRITICAL
Schneider Electric SmartConnect UPS Family - Unauthenticated Authentication Bypass via Malformed Connection
CVSS 9.8
CVE-2022-25838
HIGH
Laravel Fortify <1.11.1 - Info Disclosure
CVSS 8.1
CVE-2021-27289
CRITICAL
Ksix Zigbee Smart Home Kit <1.0.3 <1.0.7 - Replay Attack via Frame Counter
CVSS 9.1
CVE-2021-38827
HIGH
Xiongmai Camera XM-JPR2-LX - Account Takeover
CVSS 7.5
CVE-2021-46835
MEDIUM
Huawei WS7200-10 Firmware 11.0.2.13 - Traffic Hijacking via Authentication Bypass by Capture-replay
CVSS 4.3
CVE-2021-22640
HIGH
Ovarro TBox < 1.46 - Insufficiently Protected Credentials via Communication Capture
CVSS 7.5
CVE-2021-38296
HIGH
Apache Spark <3.1.2 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
219
Exploit Likelihood
High