VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (290)

page 4 of 15
  • CVE-2020-10185HigMar 5, 2020
    risk 0.56cvss 8.6epss 0.01

    The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool;…

  • CVE-2026-2540HigFeb 15, 2026
    risk 0.55cvss —epss 0.00

    The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires sending two previously captured codes in a specific sequence. As a result, the system can be forced to accept previously used (stale) rolling codes and…

  • CVE-2024-38890HigAug 2, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.

  • CVE-2025-13777HigMar 13, 2026
    risk 0.54cvss 8.3epss 0.00

    Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

  • CVE-2026-17045HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.

  • CVE-2026-9095HigMay 28, 2026
    risk 0.53cvss 8.1epss 0.00

    Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache,…

  • CVE-2026-28787HigMar 6, 2026
    risk 0.53cvss 8.2epss 0.00

    OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client and accepted back from the client…

  • CVE-2025-59023HigFeb 9, 2026
    risk 0.53cvss 8.2epss 0.00

    Crafted delegations or IP fragments can poison cached delegations in Recursor.

  • CVE-2024-3982HigAug 27, 2024
    risk 0.53cvss 8.2epss 0.00

    An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users…

  • CVE-2022-46480HigDec 5, 2023
    risk 0.53cvss 8.1epss 0.00

    Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.

  • CVE-2023-34625HigJul 20, 2023
    risk 0.53cvss 8.1epss 0.01

    ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at…

  • CVE-2022-45789HigJan 31, 2023
    risk 0.53cvss 8.1epss 0.01

    A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process…

  • CVE-2022-38766HigJan 3, 2023
    risk 0.53cvss 8.1epss 0.01

    The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open request, which allows for a replay attack.

  • CVE-2022-29475HigOct 25, 2022
    risk 0.53cvss 8.1epss 0.01

    An information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to…

  • CVE-2022-41541HigOct 18, 2022
    risk 0.53cvss 8.1epss 0.01

    TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and valid authentication token. Attackers are able to login to the web application as an admin user.

  • CVE-2022-2780HigOct 14, 2022
    risk 0.53cvss 8.1epss 0.01

    In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.

  • CVE-2022-33208HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.02

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier,…

  • CVE-2022-25159HigApr 1, 2022
    risk 0.53cvss 8.1epss 0.02

    Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric MELSEC…

  • CVE-2021-38459HigOct 22, 2021
    risk 0.53cvss 8.1epss 0.01

    The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/client connections. Using the SYSDBA permission, an attacker…

  • CVE-2021-35067HigOct 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message).