CWE-294
240 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
CVEs (240)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Huawei 2P30 Firmware P30 Pro FirmwareJun 17, 2026 Jun 4, 2019 N/A· v4 4.2 MEDIUM· v3 4.3 MEDIUM· v2 Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For th...Show more |
1Verizon 1Fios Quantum Gateway G1100 Firmware Jun 17, 2026 Apr 11, 2019 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login req...Show more |
YSoft SafeQ Server 6 allows a replay attack. |
2Chuango Eminent11A11 Pstn/lcd/rfid Touch Alarm System Firmware A8 Pstn Alarm System FirmwareAwv Plus Wifi Alarm System Firmware+8 moreJun 17, 2026 Mar 11, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded product...Show more |
1Hetronic 5Bms Hl Firmware Dc Mobile FirmwareEs Can Hl Firmware+2 moreNov 21, 2024 Jan 25, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled...Show more |
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connecti...Show more |
1Sagaradio 1Saga1 L8b Firmware Nov 21, 2024 Oct 24, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery. |
1Telecrane 11F25 10d Firmware F25 10s FirmwareF25 2d Firmware+8 moreNov 21, 2024 Oct 24, 2018 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message,...Show more |
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers. |
1Neatorobotics 3Botvac D4 Connected Firmware Botvac D6 Connected FirmwareBotvac D7 Connected FirmwareNov 21, 2024 Sep 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserve...Show more |
1O.bike 2Obike Stationless Bike Sharing Smart Locker FirmwareNov 21, 2024 Sep 14, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the loc...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Aug 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentic...Show more |
1Medtronicdiabetes 9508 Minimed Insulin Pump Firmware 522 Paradigm Real Time Firmware523 Paradigm Revel Firmware+6 moreMay 22, 2025 Aug 13, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wi...Show more |
3Debian OpensuseRedhat10Ceph Ceph StorageCeph Storage Mon+7 moreNov 21, 2024 Jul 10, 2018 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can us...Show more |
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted. |
1D Link 2Dir 130 Firmware Dir 330 FirmwareMay 13, 2026 Dec 16, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate t...Show more |
1Microsoft 2Lync Skype For BusinessMay 13, 2026 Oct 13, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, ak...Show more |
1Schneider Electric 1Modbus Firmware Jun 4, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker...Show more |
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. |
1Microsoft 2Exchange Server Windows 2000Apr 16, 2026 Mar 8, 2002 N/A· v4 N/A· v3 7.5 HIGH· v2 SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying vi...Show more |