VYPR

CWE-294

Authentication Bypass by Capture-replay

BaseIncompleteLikelihood: High

Description

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-509 · CAPEC-555 · CAPEC-561 · CAPEC-60 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-701 · CAPEC-94

CVEs mapped to this weakness (290)

page 7 of 15
  • CVE-2021-39364HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.

  • CVE-2021-31958HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.03

    Windows NTLM Elevation of Privilege Vulnerability

  • CVE-2019-12393HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.

  • CVE-2019-3915HigApr 11, 2019
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface.

  • CVE-2018-13789HigOct 10, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.

  • CVE-2018-17176HigSep 18, 2018
    risk 0.49cvss 7.5epss 0.01

    A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not…

  • CVE-2026-84003HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.00

    Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-73312HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.00

    XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers can repeatedly submit the same refresh token…

  • CVE-2026-73311HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.00

    XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed…

  • CVE-2026-41707HigAug 25, 2026
    risk 0.48cvss 7.4epss 0.00

    Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict…

  • CVE-2025-69822HigJan 22, 2026
    risk 0.48cvss 7.4epss 0.00

    An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame

  • CVE-2011-20002HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with…

  • CVE-2023-39373HigSep 3, 2023
    risk 0.48cvss 7.4epss 0.00

     A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay.

  • CVE-2024-29851HigMay 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.

  • CVE-2026-54148HigSep 18, 2026
    risk 0.46cvss 8.1epss 0.00

    http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who…

  • CVE-2026-73683HigAug 14, 2026
    risk 0.46cvss 8.1epss 0.00

    Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php.…

  • CVE-2026-53518HigJul 15, 2026
    risk 0.46cvss 8.1epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-atomic find-then-delete…

  • CVE-2026-53517HigJul 15, 2026
    risk 0.46cvss 8.1epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the…

  • CVE-2026-42602HigMay 13, 2026
    risk 0.46cvss 8.1epss 0.00

    azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single valid Azure access token for any scope the collector's configured identity can mint for to authenticate…

  • CVE-2025-1887HigMar 7, 2025
    risk 0.46cvss —epss 0.00

    SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by…