CWE-294
270 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
CVEs (270)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1O.bike 2Obike Stationless Bike Sharing Smart Locker FirmwareNov 21, 2024 Sep 14, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the loc...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Aug 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentic...Show more |
1Medtronicdiabetes 9508 Minimed Insulin Pump Firmware 522 Paradigm Real Time Firmware523 Paradigm Revel Firmware+6 moreMay 22, 2025 Aug 13, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wi...Show more |
3Debian OpensuseRedhat10Ceph Ceph StorageCeph Storage Mon+7 moreNov 21, 2024 Jul 10, 2018 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can us...Show more |
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted. |
1D Link 2Dir 130 Firmware Dir 330 FirmwareMay 13, 2026 Dec 16, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate t...Show more |
1Microsoft 2Lync Skype For BusinessMay 13, 2026 Oct 13, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, ak...Show more |
1Schneider Electric 1Modbus Firmware Jun 4, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker...Show more |
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. |
1Microsoft 2Exchange Server Windows 2000Apr 16, 2026 Mar 8, 2002 N/A· v4 N/A· v3 7.5 HIGH· v2 SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying vi...Show more |