CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

210 vulnerabilities with CWE-294
CVE-2020-6972 CRITICAL
Honeywell Fire Web Server <3.50 - Auth Bypass
CVSS 9.1
CVE-2020-10185 HIGH
YubiKey Validation Server <2.40 - Replay Attack
CVSS 8.6
CVE-2019-11856 LOW
ALEOS <4.13.0, <4.9.5, <4.4.9 - Replay Attack
CVSS 3.3
CVE-2019-20626 MEDIUM
Honda HR-V 2017 - Info Disclosure
CVSS 6.5
CVE-2019-13533 HIGH
Omron PLC - Info Disclosure
CVSS 8.1
CVE-2019-12393 HIGH
Anviz Access Control Devices - Info Disclosure
CVSS 7.5
CVE-2019-18226 CRITICAL
Honeywell equIP - Replay Attack
CVSS 9.8
CVE-2019-12887 HIGH
KeyIdentity LinOTP <2.10.5.3 - Info Disclosure
CVSS 8.1
CVE-2019-11334 LOW
Tzumi Electronics Klic Lock 1.0.9 - Auth Bypass
CVSS 3.7
CVE-2019-9158 MEDIUM
Gemalto DS3 Authentication Server <2.6.1-SP01 - Privilege Escalation
CVSS 5.7
CVE-2019-5307 MEDIUM
Huawei 4G LTE <P30 ELE-AL00 9.1.0.162/C01E160R2P1 - Message Replay
CVSS 4.2
CVE-2019-3915 HIGH
Verizon Fios Quantum Gateway G1100 Firmware - Authentication Bypass
CVSS 7.5
CVE-2019-9659 CRITICAL
Chuango 433 MHz burglar-alarm - Info Disclosure
CVSS 9.1
CVE-2018-9477 HIGH
Google Android - Missing Authorization
CVSS 7.8
CVE-2018-19025 CRITICAL
JUUKO K-808 - Command Injection
CVSS 9.8
CVE-2018-17932 CRITICAL
JUUKO K-800 - Command Injection
CVSS 9.8
CVE-2018-15498 HIGH
YSoft SafeQ Server 6 - Info Disclosure
CVSS 8.1
CVE-2018-19023 HIGH
Hetronic Nova-M <r161 - Command Injection
CVSS 8.8
CVE-2018-7356 MEDIUM
ZTE ZXR10 8905E - DoS
CVSS 5.6
CVE-2018-17903 CRITICAL
SAGA1-L8B - Command Injection
CVSS 9.1
CVE-2018-17935 HIGH
Telecrane F25 Series Radio Controls <00.0A - Command Injection
CVSS 8.1
CVE-2018-13789 HIGH
Descor Infocad FM <3.1.0.0 - Info Disclosure
CVSS 7.5
CVE-2018-17176 HIGH
Neato Botvac Connected 2.2.0 - Replay
CVSS 7.5
CVE-2018-16242 MEDIUM
oBike - Auth Bypass
CVSS 5.3
CVE-2018-7790 CRITICAL
Schneider Electric's Modicon M221 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 210
Exploit Likelihood High