CWE-294
240 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
CVEs (240)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and...Show more |
1Exposure Notifications Project 1Exposure Notifications Jun 17, 2026 Oct 7, 2020 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX value lacks a checksu...Show more |
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same crede...Show more |
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS...Show more |
1Siemens 3Sicam Mmu Firmware Sicam Sgu FirmwareSicam T FirmwareJun 17, 2026 Jul 14, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error in the challenge-response procedure could allow an attacker to replay authentica...Show more |
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client its...Show more |
1Tinxy 1Smart Wifi Door Lock Firmware Jun 17, 2026 Jun 23, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled. |
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an...Show more |
In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authentication method 'private_key_jwt' [1], OpenId specification says the followi...Show more |
Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 has a faulty implementation of Token Replay Detection. Token Replay Detection is an important def...Show more |
1Honeywell 1Notifier Webserver Jun 17, 2026 Mar 24, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser. |
The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might allow a replay attack. |
1Yubico 1Yubikey One Time Password Validation Server Jun 17, 2026 Mar 5, 2020 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service wit...Show more |
1Veraxsystems 1Network Management System Nov 21, 2024 Jan 30, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Verax NMS prior to 2.10 allows authentication via the encrypted password without knowing the cleartext password. |
1Omron 2Plc Cj Firmware Plc Cs FirmwareJun 17, 2026 Dec 16, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of indust...Show more |
Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests. |
1Honeywell 64H2w2gr1 Firmware H2w2pc1m FirmwareH2w2per3 Firmware+61 moreJun 17, 2026 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication...Show more |
KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2). |
1Tzumi 2Klic Lock Klic Smart Padlock Model 5686 FirmwareJun 17, 2026 Jun 11, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authenticat...Show more |
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control. |