VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (290)

page 6 of 15
  • CVE-2024-49595HigNov 26, 2024
    risk 0.49cvss 7.6epss 0.01

    Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2024-22066HigOct 29, 2024
    risk 0.49cvss 7.5epss 0.00

    There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.

  • CVE-2023-41890HigSep 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider. Prior to versions 1.0.3 and 2.9.2, when a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a…

  • CVE-2022-48507HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-2846HigJun 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules allows a remote unauthenticated attacker to cancel the password/keyword setting and login to the affected products by sending specially crafted packets.

  • CVE-2023-31763HigMay 24, 2023
    risk 0.49cvss 7.5epss 0.00

    Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.

  • CVE-2023-31762HigMay 24, 2023
    risk 0.49cvss 7.5epss 0.00

    Weak security in the transmitter of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to gain full access to the system via a code replay attack.

  • CVE-2023-31761HigMay 24, 2023
    risk 0.49cvss 7.5epss 0.00

    Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.

  • CVE-2023-31759HigMay 24, 2023
    risk 0.49cvss 7.5epss 0.00

    Weak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack.

  • CVE-2022-25837HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.00

    Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code…

  • CVE-2022-25836HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.00

    Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure…

  • CVE-2021-38827HigNov 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.

  • CVE-2022-44555HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.

  • CVE-2022-40621HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to…

  • CVE-2021-22640HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

  • CVE-2022-31158HigJul 15, 2022
    risk 0.49cvss 7.5epss 0.01

    LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. Users should upgrade to version 5.0 to receive a…

  • CVE-2022-33971HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and…

  • CVE-2022-29878HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by…

  • CVE-2020-27374HigApr 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

  • CVE-2021-38296HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive…