VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (290)

page 5 of 15
  • CVE-2021-27572HigMay 7, 2021
    risk 0.53cvss 8.1epss 0.03

    An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are set.

  • CVE-2020-27157HigOct 15, 2020
    risk 0.53cvss 8.1epss 0.01

    Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the data and functionality accessible to the…

  • CVE-2019-13533HigDec 16, 2019
    risk 0.53cvss 8.1epss 0.01

    In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

  • CVE-2018-15498HigMar 21, 2019
    risk 0.53cvss 8.1epss 0.01

    YSoft SafeQ Server 6 allows a replay attack.

  • CVE-2018-17935HigOct 24, 2018
    risk 0.53cvss 8.1epss 0.01

    All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

  • CVE-2017-5251HigFeb 22, 2018
    risk 0.53cvss 8.1epss 0.01

    In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.

  • CVE-2026-62911HigAug 11, 2026
    risk 0.52cvss 8.0epss 0.01

    Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-53431CriJul 30, 2026
    risk 0.52cvss —epss 0.00

    Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. Boruta accepts JWT-based client authentication…

  • CVE-2026-26232CriJul 3, 2026
    risk 0.52cvss 9.1epss 0.01

    Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

  • CVE-2026-8927CriJul 3, 2026
    risk 0.52cvss 9.1epss 0.01

    When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent…

  • CVE-2025-54810HigSep 18, 2025
    risk 0.52cvss 8.0epss 0.00

    Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over…

  • CVE-2018-9477HigNov 20, 2024
    risk 0.51cvss 7.8epss 0.00

    In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2026-73431HigAug 12, 2026
    risk 0.50cvss —epss 0.00

    Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the user's login. Although the token signature and age were…

  • CVE-2024-40715HigNov 7, 2024
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.

  • CVE-2025-61480HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

  • CVE-2025-61479HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.

  • CVE-2026-30080HigApr 8, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only security capability IA0, OpenAirInterface accepts and proceeds. This downgrade…

  • CVE-2026-20999HigMar 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.

  • CVE-2025-30072HigMay 19, 2025
    risk 0.49cvss 7.6epss 0.01

    Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.

  • CVE-2024-12137HigMar 19, 2025
    risk 0.49cvss 7.6epss 0.00

    Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. This issue affects ANKA JPD-00028: before V.01.01.