CWE-294
240 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
CVEs (240)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Omron 52Nj Pa3001 Firmware Nj Pd3001 FirmwareNj101 1000 Firmware+49 moreJun 17, 2026 Jul 4, 2022 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine au...Show more |
1Omron 57Na5 12w Firmware Na5 15w FirmwareNa5 7w Firmware+54 moreJun 17, 2026 Jul 4, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automa...Show more |
1Joyebike 1Wolf 2022 Firmware Jun 17, 2026 Jun 29, 2022 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF. |
Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST reque...Show more |
joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay. |
The replay feature in the client in Wargaming World of Warships 0.11.4 allows remote attackers to execute code when a user launches a replay from an untrusted source. |
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack. |
1Siemens 367kg8500 0aa00 0aa0 Firmware 7kg8500 0aa00 2aa0 Firmware7kg8500 0aa10 0aa0 Firmware+33 moreJun 17, 2026 May 20, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker...Show more |
1Drtrustusa 1Icheck Connect Bp Monitor Bp Testing 118 Firmware Jul 9, 2026 Apr 7, 2022 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring. |
1Mitsubishielectric 16Fx5uc 32mr/ds Ts Firmware Fx5uc 32mt/d FirmwareFx5uc 32mt/ds Ts Firmware+13 moreJun 17, 2026 Apr 1, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R ser...Show more |
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causin...Show more |
The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626. |
2Apache Oracle2Financial Services Crime And Compliance Management Studio SparkJun 17, 2026 Mar 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for...Show more |
1Schneider Electric 8Scl Series 1029 Ups Firmware Scl Series 1030 Ups FirmwareScl Series 1036 Ups Firmware+5 moreJun 17, 2026 Mar 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SM...Show more |
1Honeywell 2Hbw2per1 Firmware Hdzp252di FirmwareJun 17, 2026 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved. |
Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept. |
The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization. |
1Securitashome 1Securitashome Alarm System Firmware Jun 17, 2026 Dec 15, 2021 N/A· v4 6.8 MEDIUM· v3 5.8 MEDIUM· v2 An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30.20181117, allows an attacker to trigger arbitrary system functionality by replaying previously reco...Show more |
1Fortinet 1Forticlient Enterprise Management Server Jun 17, 2026 Dec 8, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and...Show more |
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/c...Show more |