← Back
CWE-294

240 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

JSON object

Loading...

CVEs (240)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Subnet
1Powersystem Center
Jun 17, 2026
Jun 19, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity.
1Gl Inet
1Gl Ar750s Firmware
Jul 9, 2026
Jun 13, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially...Show more
GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.Show less
1Agshome Smart Alarm Project
1Agshome Smart Alarm Firmware
Jun 17, 2026
May 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
1Mydigoo
1Dg Hamb Firmware
Jun 17, 2026
May 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weak security in the transmitter of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to gain full access to the system via a code replay attack.
1Blitzwolf
1Bw Is22 Firmware
Jun 17, 2026
May 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
1Keruistore
1Kerui W18 Firmware
Jun 17, 2026
May 24, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack.
1Nissan
1Sylphy Classic 2021 Firmware
Jun 17, 2026
May 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack. NOTE: the vendor's position is that this cannot be reproduced with genuine Nis...Show more
The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack. NOTE: the vendor's position is that this cannot be reproduced with genuine Nissan parts: for example, the combination of keyfob and door handle shown in the exploit demonstration does not match any technology that Nissan provides to customers.Show less
1Iofinnet
1Tss Lib
Jun 17, 2026
Apr 21, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoofing of messages easier. In particular, th...Show more
An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoofing of messages easier. In particular, the Schnorr proof of knowledge implemented in sch.go does not utilize a session id, context, or random nonce in the generation of the challenge. This could allow a malicious user or an eavesdropper to replay a valid proof sent in the past.Show less
1Cisco
2Duo
Duo Authentication For Windows Logon And Rdp
Jun 17, 2026
Apr 5, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session...Show more
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device. This vulnerability exists because session credentials do not properly expire. An attacker could exploit this vulnerability by replaying previously used multifactor authentication (MFA) codes to bypass MFA protection. A successful exploit could allow the attacker to gain unauthorized access to the affected device.Show less
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Apr 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass by Capture-replay in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
1Answer
1Answer
Jun 17, 2026
Mar 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Outlook Elevation of Privilege Vulnerability
1Schneider Electric
37Ecostruxure Control Expert
Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+34 more
Jun 17, 2026
Jan 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: Eco...Show more
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions) Show less
1Sinilink
1Xy Wft1 Firmware
Jun 17, 2026
Jan 20, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate using MQTT. It is possible to replay Sinilink aka SINILINK521 protocol (udp/1024)...Show more
The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate using MQTT. It is possible to replay Sinilink aka SINILINK521 protocol (udp/1024) commands interfacing directly with the target device. This, in turn, allows for an attack to control the onboard relay without requiring authentication via the mobile application. This might result in an unacceptable temperature within the target device's physical environment.Show less
1Sap
4Netweaver Application Server Abap
Netweaver Application Server Abap KernelNetweaver Application Server Abap Krnl64nuc+1 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KR...Show more
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system. Show less
1Openatom
1Openharmony
Jun 17, 2026
Jan 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack othe...Show more
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege. Show less
1Openatom
1Openharmony
Jun 17, 2026
Jan 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attac...Show more
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege. Show less
1Renault
1Zoe E Tech Firmware
Jun 17, 2026
Jan 3, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open request, which allows for a replay attack.
1Mozilla
1Thunderbird
Jun 17, 2026
Dec 22, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, th...Show more
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid signature. If an attacker performed a replay attack, in which an old email with old contents are resent at a later time, it could lead the victim to believe that the statements in the email are current. Fixed versions of Thunderbird will require that the signature's date roughly matches the displayed date of the email. This vulnerability affects Thunderbird < 102 and Thunderbird < 91.11.Show less
1Bluetooth
1Bluetooth Core Specification
Jun 17, 2026
Dec 12, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure...Show more
Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code pairing if the MITM negotiates BR/EDR Secure Simple Pairing in Secure Connections mode using the Passkey association model with the pairing Initiator and BR/EDR Legacy PIN code pairing with the pairing Responder and brute forces the Passkey entered by the user into the Responder as a 6-digit PIN code. The MITM attacker can use the identified PIN code value as the Passkey value to complete authentication with the Initiator via Bluetooth pairing method confusion.Show less