CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

210 vulnerabilities with CWE-294
CVE-2021-31958 HIGH
Windows NTLM - Privilege Escalation
CVSS 7.5
CVE-2021-27572 HIGH
Emote Remote Mouse <4.0.0.0 - Auth Bypass
CVSS 8.1
CVE-2021-22267 MEDIUM
Idelji Web ViewPoint Suite - SSRF
CVSS 5.9
CVE-2021-25835 HIGH
Cosmos Network Ethermint <= v0.4.0 - SSRF
CVSS 7.5
CVE-2021-25834 HIGH
Cosmos Network Ethermint <= 0.4.0 - RCE
CVSS 7.5
CVE-2020-35473 MEDIUM
Bluetooth Core Specification < 5.2 - Information Disclosure
CVSS 4.3
CVE-2020-27374 HIGH
Dr Trust USA iCheck Connect BP Monitor <1.2.1 - Info Disclosure
CVSS 7.5
CVE-2020-23178 MEDIUM
PHP-Fusion 9.03.50 - Info Disclosure
CVSS 5.4
CVE-2020-28713 MEDIUM
Night Owl Smart Doorbell FW <20190505 - Info Disclosure
CVSS 6.5
CVE-2020-27269 MEDIUM
SOOIL Developments Co., Ltd Diabecare RS - Replay Attack
CVSS 5.7
CVE-2020-26172 MEDIUM
Tangro Business Workflow <1.18.1 - Auth Bypass
CVSS 4.2
CVE-2020-35551 CRITICAL
Samsung O(8.x)-Q(10.0) Exynos - Info Disclosure
CVSS 9.8
CVE-2020-14302 MEDIUM
Keycloak <13.0.0 - SSRF
CVSS 4.9
CVE-2020-25660 HIGH
Cephx <15.2.6,14.2.14 - Privilege Escalation
CVSS 8.8
CVE-2020-13799 MEDIUM
Western Digital - Info Disclosure
CVSS 6.8
CVE-2020-12355 MEDIUM
Intel Trusted Execution Engine < 4.0.30 - Authentication Bypass
CVSS 6.8
CVE-2020-27157 HIGH
Veritas APTARE <10.5 - Auth Bypass
CVSS 8.1
CVE-2020-24722 MEDIUM
GAEN protocol <2020-10-05 - Info Disclosure
CVSS 5.9
CVE-2020-15688 HIGH
GoAhead <5.1.2 - Auth Bypass
CVSS 8.8
CVE-2020-10045 HIGH
SICAM MMU,SGU,T <V2.05,V2.18 - Auth Bypass
CVSS 8.8
CVE-2020-4042 MEDIUM
Bareos <19.2.8 - Info Disclosure
CVSS 6.8
CVE-2020-9438 MEDIUM
Tinxy Door Lock <3.2 - Privilege Escalation
CVSS 5.9
CVE-2020-12692 MEDIUM
OpenStack Keystone <15.0.1-16.0.0 - Info Disclosure
CVSS 5.4
CVE-2020-5300 MEDIUM
Hydra <1.4.0+oryOS.17 - Info Disclosure
CVSS 5.8
CVE-2020-5261 HIGH
Sustainsys.Saml2 >2.0.0 <2.5.0 - Privilege Escalation
CVSS 8.2
Details
Vulnerabilities 210
Exploit Likelihood High