CWE-294
Authentication Bypass by Capture-replay
Description
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94
CVEs mapped to this weakness (259)
page 6 of 13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25836 | Hig | 0.49 | 7.5 | 0.00 | Dec 12, 2022 | Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure… | ||
| CVE-2021-38827 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2022 | Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover. | ||
| CVE-2022-44555 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable. | ||
| CVE-2022-40621 | Hig | 0.49 | 7.5 | 0.01 | Sep 13, 2022 | Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to… | ||
| CVE-2021-22640 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. | ||
| CVE-2022-31158 | Hig | 0.49 | 7.5 | 0.01 | Jul 15, 2022 | LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. Users should upgrade to version 5.0 to receive a… | ||
| CVE-2022-33971 | Hig | 0.49 | 7.5 | 0.01 | Jul 4, 2022 | Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and… | ||
| CVE-2022-29878 | Hig | 0.49 | 7.5 | 0.01 | May 20, 2022 | A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by… | ||
| CVE-2020-27374 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2022 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring. | ||
| CVE-2021-38296 | Hig | 0.49 | 7.5 | 0.02 | Mar 10, 2022 | Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive… | ||
| CVE-2021-39364 | Hig | 0.49 | 7.5 | 0.01 | Feb 24, 2022 | Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved. | ||
| CVE-2021-31958 | Hig | 0.49 | 7.5 | 0.03 | Jun 8, 2021 | Windows NTLM Elevation of Privilege Vulnerability | ||
| CVE-2019-12393 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2019 | Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests. | ||
| CVE-2019-3915 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2019 | Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface. | ||
| CVE-2018-13789 | Hig | 0.49 | 7.5 | 0.01 | Oct 10, 2018 | An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers. | ||
| CVE-2018-17176 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2018 | A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not… | ||
| CVE-2025-69822 | Hig | 0.48 | 7.4 | 0.00 | Jan 22, 2026 | An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame | ||
| CVE-2011-20002 | Hig | 0.48 | 7.4 | 0.00 | Oct 14, 2025 | A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with… | ||
| CVE-2023-39373 | Hig | 0.48 | 7.4 | 0.00 | Sep 3, 2023 | A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay. | ||
| CVE-2024-29851 | Hig | 0.47 | 7.2 | 0.01 | May 22, 2024 | Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. |
- risk 0.49cvss 7.5epss 0.00
Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure…
- risk 0.49cvss 7.5epss 0.01
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.
- risk 0.49cvss 7.5epss 0.00
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
- risk 0.49cvss 7.5epss 0.01
Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to…
- risk 0.49cvss 7.5epss 0.01
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
- risk 0.49cvss 7.5epss 0.01
LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. Users should upgrade to version 5.0 to receive a…
- risk 0.49cvss 7.5epss 0.01
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by…
- risk 0.49cvss 7.5epss 0.01
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.
- risk 0.49cvss 7.5epss 0.02
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive…
- risk 0.49cvss 7.5epss 0.01
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
- risk 0.49cvss 7.5epss 0.03
Windows NTLM Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.
- risk 0.49cvss 7.5epss 0.01
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
- risk 0.49cvss 7.5epss 0.01
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not…
- risk 0.48cvss 7.4epss 0.00
An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame
- risk 0.48cvss 7.4epss 0.00
A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with…
- risk 0.48cvss 7.4epss 0.00
A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay.
- risk 0.47cvss 7.2epss 0.01
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.