VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (259)

page 3 of 13
  • CVE-2024-38284HigJun 13, 2024
    risk 0.57cvss epss 0.00

    Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.

  • CVE-2024-29850HigMay 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

  • CVE-2023-46892HigJan 23, 2024
    risk 0.57cvss 8.8epss 0.00

    The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication to execute unauthorized commands or actions (e.g., thermostat's temperature).

  • CVE-2023-39547HigNov 17, 2023
    risk 0.57cvss 8.8epss 0.01

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

  • CVE-2023-1537CriMar 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.

  • CVE-2022-31277HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.

  • CVE-2022-31265HigMay 26, 2022
    risk 0.57cvss 8.8epss 0.02

    The replay feature in the client in Wargaming World of Warships 0.11.4 allows remote attackers to execute code when a user launches a replay from an untrusted source.

  • CVE-2022-22936HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be…

  • CVE-2021-45327CriFeb 8, 2022
    risk 0.57cvss 9.8epss 0.02

    Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.

  • CVE-2020-25660HigNov 23, 2020
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to…

  • CVE-2020-10045HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error in the challenge-response procedure could allow an attacker to replay authentication traffic and gain access to protected areas of the web…

  • CVE-2018-19023HigJan 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

  • CVE-2026-34021HigJun 15, 2026
    risk 0.56cvss epss 0.00

    The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the…

  • CVE-2021-27662HigSep 15, 2021
    risk 0.56cvss 8.6epss 0.01

    The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01

  • CVE-2020-10185HigMar 5, 2020
    risk 0.56cvss 8.6epss 0.01

    The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool;…

  • CVE-2026-2540HigFeb 15, 2026
    risk 0.55cvss epss 0.00

    The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires sending two previously captured codes in a specific sequence. As a result, the system can be forced to accept previously used (stale) rolling codes and…

  • CVE-2024-38890HigAug 2, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.

  • CVE-2025-13777HigMar 13, 2026
    risk 0.54cvss 8.3epss 0.00

    Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

  • CVE-2026-9095HigMay 28, 2026
    risk 0.53cvss 8.1epss 0.00

    Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache,…

  • CVE-2026-28787HigMar 6, 2026
    risk 0.53cvss 8.2epss 0.00

    OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client…