VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (290)

page 2 of 15
  • CVE-2017-6034CriJun 30, 2017
    risk 0.64cvss 9.8epss 0.05

    An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and…

  • CVE-2025-6030CriJun 13, 2025
    risk 0.61cvss —epss 0.00

    Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto.  Attack confirmed on other KIA…

  • CVE-2025-6029CriJun 13, 2025
    risk 0.61cvss —epss 0.01

    Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of…

  • CVE-2017-6823HigMar 12, 2017
    risk 0.61cvss 8.8epss 0.08

    Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.

  • CVE-2024-4009CriJun 5, 2024
    risk 0.60cvss 9.2epss 0.00

    Replay Attack in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KNX Bus-System

  • CVE-2026-53424CriAug 20, 2026
    risk 0.59cvss —epss 0.00

    Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose…

  • CVE-2021-27289CriApr 15, 2025
    risk 0.59cvss 9.1epss 0.01

    A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As…

  • CVE-2025-26201CriFeb 24, 2025
    risk 0.59cvss 9.1epss 0.01

    Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.

  • CVE-2023-27987CriApr 10, 2023
    risk 0.59cvss 9.1epss 0.01

    In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the version of Linkis to…

  • CVE-2023-0014CriJan 10, 2023
    risk 0.59cvss 9.0epss 0.01

    SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system…

  • CVE-2020-6972CriMar 24, 2020
    risk 0.59cvss 9.1epss 0.01

    In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.

  • CVE-2019-9659CriMar 11, 2019
    risk 0.59cvss 9.1epss 0.01

    The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent…

  • CVE-2018-17903CriOct 24, 2018
    risk 0.59cvss 9.1epss 0.02

    SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.

  • CVE-2020-15688HigJul 23, 2020
    risk 0.58cvss 8.8epss 0.04

    The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to protect the underlying communication channel.

  • CVE-2017-11786HigOct 13, 2017
    risk 0.58cvss 8.8epss 0.09

    Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, aka "Skype for Business Elevation of Privilege Vulnerability."

  • CVE-2026-55250HigSep 8, 2026
    risk 0.57cvss —epss 0.01

    Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-performance relational caching layers. Any…

  • CVE-2026-69676HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

  • CVE-2026-86219CriSep 6, 2026
    risk 0.57cvss 9.8epss 0.00

    Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client…

  • CVE-2026-65905CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is…

  • CVE-2026-11856CriJul 3, 2026
    risk 0.57cvss 9.8epss 0.01

    Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header…