VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (259)

page 6 of 13
  • CVE-2022-25836HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.00

    Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure…

  • CVE-2021-38827HigNov 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.

  • CVE-2022-44555HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.

  • CVE-2022-40621HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to…

  • CVE-2021-22640HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

  • CVE-2022-31158HigJul 15, 2022
    risk 0.49cvss 7.5epss 0.01

    LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. Users should upgrade to version 5.0 to receive a…

  • CVE-2022-33971HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and…

  • CVE-2022-29878HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by…

  • CVE-2020-27374HigApr 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

  • CVE-2021-38296HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive…

  • CVE-2021-39364HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.

  • CVE-2021-31958HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.03

    Windows NTLM Elevation of Privilege Vulnerability

  • CVE-2019-12393HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.

  • CVE-2019-3915HigApr 11, 2019
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface.

  • CVE-2018-13789HigOct 10, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.

  • CVE-2018-17176HigSep 18, 2018
    risk 0.49cvss 7.5epss 0.01

    A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not…

  • CVE-2025-69822HigJan 22, 2026
    risk 0.48cvss 7.4epss 0.00

    An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame

  • CVE-2011-20002HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with…

  • CVE-2023-39373HigSep 3, 2023
    risk 0.48cvss 7.4epss 0.00

     A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay.

  • CVE-2024-29851HigMay 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.