← Back
CWE-294

270 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

JSON object

Loading...

CVEs (270)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Saltstack
1Salt
Jun 17, 2026
Mar 29, 2022
N/A· v4
8.8 HIGH· v3
5.4 MEDIUM· v2
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causin...Show more
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be re-played. A sufficient craft attacker could gain root access on minion under certain scenarios.Show less
1Honda
1Civic 2018 Firmware
Jun 17, 2026
Mar 23, 2022
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.
2Apache
Oracle
2Financial Services Crime And Compliance Management Studio
Spark
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for...Show more
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or laterShow less
1Schneider Electric
8Scl Series 1029 Ups Firmware
Scl Series 1030 Ups FirmwareScl Series 1036 Ups Firmware+5 more
Jun 17, 2026
Mar 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SM...Show more
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC Series ID=1018: UPS 04.2 and prior), SMTL Series (SMTL Series ID=1026: UPS 02.9 and prior), SCL Series (SCL Series ID=1029: UPS 02.5 and prior / SCL Series ID=1030: UPS 02.5 and prior / SCL Series ID=1036: UPS 02.5 and prior / SCL Series ID=1037: UPS 03.1 and prior), SMX Series (SMX Series ID=1031: UPS 03.1 and prior)Show less
1Honeywell
2Hbw2per1 Firmware
Hdzp252di Firmware
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
1Laravel
1Fortify
Jun 17, 2026
Feb 24, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.
1Honda
1Civic 2012
Jun 17, 2026
Jan 6, 2022
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization.
1Securitashome
1Securitashome Alarm System Firmware
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.8 MEDIUM· v3
5.8 MEDIUM· v2
An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30.20181117, allows an attacker to trigger arbitrary system functionality by replaying previously reco...Show more
An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30.20181117, allows an attacker to trigger arbitrary system functionality by replaying previously recorded signals. This lets an adversary, among other things, disarm an armed system.Show less
1Fortinet
1Forticlient Enterprise Management Server
Jun 17, 2026
Dec 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and...Show more
An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages.Show less
1Auvesy
1Versiondog
Jun 17, 2026
Oct 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/c...Show more
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/client connections. Using the SYSDBA permission, an attacker can change user passwords or delete the database.Show less
1Meross
1Msg100 Firmware
Jun 17, 2026
Oct 7, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message).
1Google
1Android
Jun 17, 2026
Oct 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.
1Johnsoncontrols
1Kantech Kt 1 Door Controller Firmware
Jun 17, 2026
Sep 15, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01
1Dm Fingertool Project
1Dm Fingertool
Jun 17, 2026
Jul 26, 2021
N/A· v4
7.1 HIGH· v3
5.6 MEDIUM· v2
DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing local attackers to bypass user authentication and access all features and data on the USB.
1Php Fusion
1Php Fusion
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jun 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Windows NTLM Elevation of Privilege Vulnerability
1Nightowlsp
1Smart Doorbell Firmware
Jun 17, 2026
Jun 8, 2021
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote users to send push notification events via an exposed PNS server. A remote attacker can passively record...Show more
Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote users to send push notification events via an exposed PNS server. A remote attacker can passively record push notification events which are sent over an insecure web request. The web service does not authenticate requests, and allows attackers to send an indefinite amount of motion or doorbell events to a user's mobile application by either replaying or deliberately crafting false events.Show less
1Remotemouse
1Emote Remote Mouse
Jun 17, 2026
May 7, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are se...Show more
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are set.Show less
1Hpe
1Web Viewpoint
Jun 17, 2026
Feb 9, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, an...Show more
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY, T0952H01^AAG through T0952H01^AAQ, T0986H01 through T0986H01^AAE, T0665H01^AAO, and T0662H01^AAO (J and H).Show less
1Chainsafe
1Ethermint
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a veri...Show more
Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch, which enables "cross-chain transaction replay" attack.Show less