CWE-294
270 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
CVEs (270)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 17, 2026 Mar 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Outlook Elevation of Privilege Vulnerability |
1Schneider Electric 37Ecostruxure Control Expert Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+34 moreJun 17, 2026 Jan 31, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: Eco...Show more |
The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate using MQTT. It is possible to replay Sinilink aka SINILINK521 protocol (udp/1024)...Show more |
1Sap 4Netweaver Application Server Abap Netweaver Application Server Abap KernelNetweaver Application Server Abap Krnl64nuc+1 moreJun 17, 2026 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KR...Show more |
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack othe...Show more |
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attac...Show more |
The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open request, which allows for a replay attack. |
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, th...Show more |
1Bluetooth 1Bluetooth Core Specification Jun 17, 2026 Dec 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure...Show more |
1Bluetooth 1Bluetooth Core Specification Jun 17, 2026 Dec 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passk...Show more |
1Electronic Shelf Label Protocol Project 1Electronic Shelf Label Protocol Jun 17, 2026 Nov 27, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 board, does not use authentication, which allows attackers to change label values v...Show more |
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover. |
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable. |
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.0 < V1.17.2), Mendix SAML (Mendix 8 compatible) (All versions <...Show more |
1Bluetooth 1Bluetooth Core Specification Jun 17, 2026 Nov 8, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2,...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 An information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted man-in-the-middle attack can lead to increased privileges...Show more |
TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and valid authentication token. Attackers are able to login to the web application a...Show more |
In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack. |
mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage. |