VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (290)

page 12 of 15
  • CVE-2025-68671MedJan 15, 2026
    risk 0.35cvss 6.5epss 0.00

    lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network…

  • CVE-2025-69197MedJan 6, 2026
    risk 0.35cvss 6.5epss 0.00

    Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not sufficiently marked as used…

  • CVE-2024-52534MedDec 25, 2024
    risk 0.35cvss 5.4epss 0.00

    Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

  • CVE-2024-5249MedJul 30, 2024
    risk 0.35cvss 5.4epss 0.00

    In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.

  • CVE-2023-36857MedOct 19, 2023
    risk 0.35cvss 5.4epss 0.00

    Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allow an attacker to replay older captured packets of traffic to the device to gain access.

  • CVE-2022-27254MedMar 23, 2022
    risk 0.35cvss 5.3epss 0.01

    The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.

  • CVE-2021-46145MedJan 6, 2022
    risk 0.35cvss 5.3epss 0.03

    The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization.

  • CVE-2021-41030MedDec 8, 2021
    risk 0.35cvss 5.4epss 0.01

    An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages.

  • CVE-2020-23178MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.

  • CVE-2020-12692MedMay 7, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.

  • CVE-2018-16242MedSep 14, 2018
    risk 0.35cvss 5.3epss 0.01

    oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

  • CVE-2018-14781MedAug 13, 2018
    risk 0.35cvss 5.3epss 0.01

    Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller…

  • CVE-2026-82220MedAug 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

  • CVE-2023-33854MedJun 22, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.

  • CVE-2026-6420MedMay 6, 2026
    risk 0.34cvss 6.3epss 0.00

    A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation…

  • CVE-2026-24027MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Crafted zones can lead to increased incoming network traffic.

  • CVE-2025-35057MedOct 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the NIX service account.

  • CVE-2025-9100MedAug 18, 2025
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by capture-replay. The attack can be…

  • CVE-2023-50128MedJan 11, 2024
    risk 0.34cvss 5.3epss 0.00

    The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for each request, which results in an attacker being able to conduct replay attacks to bring the alarm system to a disarmed state.

  • CVE-2022-51016MedSep 7, 2026
    risk 0.33cvss 6.1epss 0.00

    PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid login from another player's session (for…