CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

219 vulnerabilities with CWE-294
CVE-2020-27157 HIGH
Veritas APTARE < 10.5 - Unauthenticated Authentication Bypass via Capture-replay
CVSS 8.1
CVE-2020-24722 MEDIUM
GAEN protocol <2020-10-05 - Info Disclosure
CVSS 5.9
CVE-2020-15688 HIGH
GoAhead < 5.1.2 - Unauthenticated Authentication Bypass via Digest Nonce Reuse
CVSS 8.8
CVE-2020-10045 HIGH
SICAM MMU,SGU,T <V2.05,V2.18 - Auth Bypass
CVSS 8.8
CVE-2020-4042 MEDIUM
bareos < 19.2.8 - Authentication Bypass via CRAM-MD5 Challenge Replay
CVSS 6.8
CVE-2020-9438 MEDIUM
Tinxy Door Lock <3.2 - Privilege Escalation
CVSS 5.9
CVE-2020-12692 MEDIUM
OpenStack Keystone <15.0.1-16.0.0 - Info Disclosure
CVSS 5.4
CVE-2020-5300 MEDIUM
Hydra <1.4.0+oryOS.17 - Info Disclosure
CVSS 5.8
CVE-2020-5261 HIGH
Sustainsys.Saml2 >2.0.0 <2.5.0 - Privilege Escalation
CVSS 8.2
CVE-2020-6972 CRITICAL
Honeywell Fire Web Server <3.50 - Auth Bypass
CVSS 9.1
CVE-2020-10185 HIGH
YubiKey Validation Server <2.40 - Replay Attack
CVSS 8.6
CVE-2019-11856 LOW
ALEOS <4.13.0, <4.9.5, <4.4.9 - Replay Attack
CVSS 3.3
CVE-2019-20626 MEDIUM
Honda HR-V 2017 Firmware - Authentication Bypass via RF Signal Replay
CVSS 6.5
CVE-2019-13533 HIGH
Omron PLC CJ and CS Series - Authentication Bypass by Capture-replay
CVSS 8.1
CVE-2019-12393 HIGH
Anviz Access Control Devices - Info Disclosure
CVSS 7.5
CVE-2019-18226 CRITICAL
Honeywell equIP and Performance Series - Authentication Bypass via Replay Attack
CVSS 9.8
CVE-2019-12887 HIGH
KeyIdentity LinOTP <2.10.5.3 - Info Disclosure
CVSS 8.1
CVE-2019-11334 LOW
Tzumi Electronics Klic Lock 1.0.9 - Auth Bypass
CVSS 3.7
CVE-2019-9158 MEDIUM
Gemalto DS3 Authentication Server <2.6.1-SP01 - Privilege Escalation
CVSS 5.7
CVE-2019-5307 MEDIUM
Huawei 4G LTE <P30 ELE-AL00 9.1.0.162/C01E160R2P1 - Message Replay
CVSS 4.2
CVE-2019-3915 HIGH
Verizon Fios Quantum Gateway G1100 Firmware 02.01.00.05 - Unauthenticated Authentication Bypass via Capture-replay
CVSS 7.5
CVE-2019-9659 CRITICAL
Chuango 433 MHz burglar-alarm - Info Disclosure
CVSS 9.1
CVE-2018-9477 HIGH
Android - Missing Authorization in Development Options
CVSS 7.8
CVE-2018-19025 CRITICAL
JUUKO K-808 Firmware - Authentication Bypass by Capture-replay
CVSS 9.8
CVE-2018-17932 CRITICAL
JUUKO K-800 Firmware - Authentication Bypass via Replay Attack
CVSS 9.8
Details
Vulnerabilities 219
Exploit Likelihood High