CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

219 vulnerabilities with CWE-294
CVE-2022-37011 CRITICAL
Mendix SAML <1.17.0, <2.3.0, <3.3.0 - Auth Bypass
CVSS 9.8
CVE-2022-36089 HIGH
KubeVela <1.4.11, <1.5.4 - Auth Bypass
CVSS 8.2
CVE-2022-37418 MEDIUM
Nissan, Kia, and Hyundai Firmware < 2017 - Authentication Bypass via RollBack Replay Attack
CVSS 6.4
CVE-2022-37305 MEDIUM
Honda Firmware < 2018 - Authentication Bypass via RollBack Replay Attack
CVSS 6.4
CVE-2022-36945 MEDIUM
Mazda Vehicles Through 2020 - Remote Unlock via RollBack Key-Fob Replay
CVSS 6.4
CVE-2022-31158 HIGH
LTI 1.3 Tool Library <5.0 - Info Disclosure
CVSS 7.5
CVE-2022-29593 MEDIUM
Dingtian DT-R002 3.1.276A - Unauthenticated Authentication Bypass via HTTP Request Replay
CVSS 5.9
CVE-2022-33971 HIGH
OMRON NX7/NX1/NJ Series Firmware < 1.28/1.48 - Authentication Bypass by Capture-replay
CVSS 7.5
CVE-2022-33208 HIGH
Machine automation controller - Auth Bypass
CVSS 8.1
CVE-2022-30467 MEDIUM
Joyebike Wolf 2022 Firmware - Denial of Service via RF Key Fob Request Jamming
CVSS 6.8
CVE-2022-31277 HIGH
Xiaomi Lamp 1 <v2.0.4_0066 - Open Redirect
CVSS 8.8
CVE-2022-30466 MEDIUM
joybike Wolf Firmware - Authentication Bypass via Capture-replay
CVSS 6.5
CVE-2022-31265 HIGH
Wargaming World of Warships <0.11.4 - RCE
CVSS 8.8
CVE-2022-29334 CRITICAL
H v1.0 - Auth Bypass
CVSS 9.8
CVE-2022-29878 HIGH
SICAM T < V3.0 - Info Disclosure
CVSS 7.5
CVE-2022-25159 HIGH
Mitsubishielectric Fx5uc Firmware - Authentication Bypass
CVSS 8.1
CVE-2022-22936 HIGH
SaltStack Salt <3002.8-3004.1 - Privilege Escalation
CVSS 8.8
CVE-2022-27254 MEDIUM
Honda Civic 2018 Firmware - Authentication Bypass via RF Signal Replay Attack
CVSS 5.3
CVE-2022-22806 CRITICAL
Schneider Electric SmartConnect UPS Family - Unauthenticated Authentication Bypass via Malformed Connection
CVSS 9.8
CVE-2022-25838 HIGH
Laravel Fortify <1.11.1 - Info Disclosure
CVSS 8.1
CVE-2021-27289 CRITICAL
Ksix Zigbee Smart Home Kit <1.0.3 <1.0.7 - Replay Attack via Frame Counter
CVSS 9.1
CVE-2021-38827 HIGH
Xiongmai Camera XM-JPR2-LX - Account Takeover
CVSS 7.5
CVE-2021-46835 MEDIUM
Huawei WS7200-10 Firmware 11.0.2.13 - Traffic Hijacking via Authentication Bypass by Capture-replay
CVSS 4.3
CVE-2021-22640 HIGH
Ovarro TBox < 1.46 - Insufficiently Protected Credentials via Communication Capture
CVSS 7.5
CVE-2021-38296 HIGH
Apache Spark <3.1.2 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 219
Exploit Likelihood High