CWE-294
High likelihoodAuthentication Bypass by Capture-replay
Parent: CWE-1390 - Weak Authentication
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
210 vulnerabilities with CWE-294
CVE-2020-6972
CRITICAL
Honeywell Fire Web Server <3.50 - Auth Bypass
CVSS 9.1
CVE-2020-10185
HIGH
YubiKey Validation Server <2.40 - Replay Attack
CVSS 8.6
CVE-2019-11856
LOW
ALEOS <4.13.0, <4.9.5, <4.4.9 - Replay Attack
CVSS 3.3
CVE-2019-20626
MEDIUM
Honda HR-V 2017 - Info Disclosure
CVSS 6.5
CVE-2019-13533
HIGH
Omron PLC - Info Disclosure
CVSS 8.1
CVE-2019-12393
HIGH
Anviz Access Control Devices - Info Disclosure
CVSS 7.5
CVE-2019-18226
CRITICAL
Honeywell equIP - Replay Attack
CVSS 9.8
CVE-2019-12887
HIGH
KeyIdentity LinOTP <2.10.5.3 - Info Disclosure
CVSS 8.1
CVE-2019-11334
LOW
Tzumi Electronics Klic Lock 1.0.9 - Auth Bypass
CVSS 3.7
CVE-2019-9158
MEDIUM
Gemalto DS3 Authentication Server <2.6.1-SP01 - Privilege Escalation
CVSS 5.7
CVE-2019-5307
MEDIUM
Huawei 4G LTE <P30 ELE-AL00 9.1.0.162/C01E160R2P1 - Message Replay
CVSS 4.2
CVE-2019-3915
HIGH
Verizon Fios Quantum Gateway G1100 Firmware - Authentication Bypass
CVSS 7.5
CVE-2019-9659
CRITICAL
Chuango 433 MHz burglar-alarm - Info Disclosure
CVSS 9.1
CVE-2018-9477
HIGH
Google Android - Missing Authorization
CVSS 7.8
CVE-2018-19025
CRITICAL
JUUKO K-808 - Command Injection
CVSS 9.8
CVE-2018-17932
CRITICAL
JUUKO K-800 - Command Injection
CVSS 9.8
CVE-2018-15498
HIGH
YSoft SafeQ Server 6 - Info Disclosure
CVSS 8.1
CVE-2018-19023
HIGH
Hetronic Nova-M <r161 - Command Injection
CVSS 8.8
CVE-2018-7356
MEDIUM
ZTE ZXR10 8905E - DoS
CVSS 5.6
CVE-2018-17903
CRITICAL
SAGA1-L8B - Command Injection
CVSS 9.1
CVE-2018-17935
HIGH
Telecrane F25 Series Radio Controls <00.0A - Command Injection
CVSS 8.1
CVE-2018-13789
HIGH
Descor Infocad FM <3.1.0.0 - Info Disclosure
CVSS 7.5
CVE-2018-17176
HIGH
Neato Botvac Connected 2.2.0 - Replay
CVSS 7.5
CVE-2018-16242
MEDIUM
oBike - Auth Bypass
CVSS 5.3
CVE-2018-7790
CRITICAL
Schneider Electric's Modicon M221 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities
210
Exploit Likelihood
High