VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (259)

page 1 of 13
  • CVE-2023-23397CriKEVMar 14, 2023
    risk 0.83cvss 9.8epss 0.97

    Microsoft Outlook Elevation of Privilege Vulnerability

  • CVE-2017-3191CriDec 16, 2017
    risk 0.69cvss 9.8epss 0.63

    D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some…

  • CVE-2023-49231CriMar 29, 2024
    risk 0.67cvss 9.8epss 0.43

    An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.

  • CVE-2025-49752CriNov 20, 2025
    risk 0.65cvss 10.0epss 0.01

    Azure Bastion Elevation of Privilege Vulnerability

  • CVE-2022-22806CriMar 9, 2022
    risk 0.65cvss 9.8epss 0.12

    A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC…

  • CVE-2026-68079CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be…

  • CVE-2025-67135CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

  • CVE-2025-65552CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid…

  • CVE-2024-38438CriJul 21, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link - CWE-294: Authentication Bypass by Capture-replay

  • CVE-2023-47435CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.

  • CVE-2023-30909CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in some OneView APIs.

  • CVE-2022-44457CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.0 < V1.17.2), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 8 compatible) (All versions >=…

  • CVE-2022-37011CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 9 compatible, New Track) (All versions < V3.3.1), Mendix SAML (Mendix 9 compatible, Upgrade Track)…

  • CVE-2022-29334CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.

  • CVE-2020-35551CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CVE-2020-13799. The Samsung…

  • CVE-2018-19025CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.02

    In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.).

  • CVE-2018-17932CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.02

    JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, which could allow attackers to replay commands, control the device, view commands, or cause the device to stop running.

  • CVE-2019-18226CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.

  • CVE-2018-7790CriAug 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability…

  • CVE-2017-6034CriJun 30, 2017
    risk 0.64cvss 9.8epss 0.05

    An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and…