CWE-294— Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).— MITRE CWE catalog
297 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-294page 1 of 6
- CVE-2023-23397CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-14
Microsoft Outlook Elevation of Privilege Vulnerability
- CVE-2025-49752CRITICALCVSS 10.0EG 10.02025-11-20
Azure Bastion Elevation of Privilege Vulnerability
- CVE-2026-88278CRITICALCVSS 9.8EG 9.82026-09-10
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
- CVE-2026-86219CRITICALCVSS 9.8EG 9.82026-09-06
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares th…
- CVE-2026-65905CRITICALCVSS 9.8EG 9.82026-08-25
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the re…
- CVE-2026-68079CRITICALCVSS 9.8EG 9.82026-08-06
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement tha…
- CVE-2026-56453CRITICALCVSS 9.8EG 9.82026-07-16
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to m…
- CVE-2026-28564CRITICALCVSS 9.8EG 9.82026-07-10
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are reco…
- CVE-2026-11856CRITICALCVSS 9.8EG 9.82026-07-03
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly …
- CVE-2026-32987CRITICALCVSS 9.8EG 9.82026-03-29
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairi…
- CVE-2026-30789CRITICALCVSS 9.8EG 9.82026-03-05
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, p…
- CVE-2025-67135CRITICALCVSS 9.8EG 9.82026-02-11
Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.
- CVE-2025-65552CRITICALCVSS 9.8EG 9.82026-01-12
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attack…
- CVE-2024-38438CRITICALCVSS 9.8EG 9.82024-07-21
D-Link - CWE-294: Authentication Bypass by Capture-replay
- CVE-2023-47435CRITICALCVSS 9.8EG 9.82024-04-19
An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.
- CVE-2023-49231CRITICALCVSS 9.8EG 9.82024-03-29
An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.
- CVE-2023-30909CRITICALCVSS 9.8EG 9.82023-09-14
A remote authentication bypass issue exists in some OneView APIs.
- CVE-2023-1537CRITICALCVSS 9.8EG 9.82023-03-21
Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2022-44457CRITICALCVSS 9.8EG 9.82022-11-08
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.0 < V1.17.2), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAM…
- CVE-2022-37011CRITICALCVSS 9.8EG 9.82022-09-13
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 9 compatible, New Track) (All versions < V3.3.1), Mendix SAML…
- CVE-2022-29334CRITICALCVSS 9.8EG 9.82022-05-24
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
- CVE-2022-22806CRITICALCVSS 9.8EG 9.82022-03-09
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: U…
- CVE-2020-35551CRITICALCVSS 9.8EG 9.82020-12-18
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a relate…
- CVE-2018-19025CRITICALCVSS 9.8EG 9.82020-11-02
In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.).
- CVE-2018-17932CRITICALCVSS 9.8EG 9.82020-11-02
JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, which could allow attackers to replay commands, control the device, view commands, or cause the device …
- CVE-2019-18226CRITICALCVSS 9.8EG 9.82019-10-31
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained…
- CVE-2018-7790CRITICALCVSS 9.8EG 9.82018-08-29
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If…
- CVE-2017-3191CRITICALCVSS 9.8EG 9.82017-12-16
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in …
- CVE-2017-6034CRITICALCVSS 9.8EG 9.82017-06-30
An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the foll…
- CVE-2023-0014CRITICALCVSS 9.0EG 9.82023-01-10
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22E…
- CVE-2022-45789CRITICALCVSS 8.1EG 9.82023-01-31
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Ex…
- CVE-2021-22640CRITICALCVSS 7.5EG 9.82022-07-28
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
- CVE-2025-6030CRITICALCVSS 9.4EG 9.42025-06-13
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA So…
- CVE-2025-6029CRITICALCVSS 9.4EG 9.42025-06-13
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack.…
- CVE-2026-103655CRITICALCVSS 9.3EG 9.32026-10-01
MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow whe…
- CVE-2024-4009CRITICALCVSS 9.2EG 9.22024-06-05
Replay Attack in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KNX Bus-System
- CVE-2026-53424CRITICALCVSS 9.1EG 9.12026-08-20
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esa…
- CVE-2026-53431CRITICALCVSS 9.1EG 9.12026-07-30
Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. Boruta acce…
- CVE-2026-51597CRITICALCVSS 9.1EG 9.12026-07-09
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response va…
- CVE-2026-26232CRITICALCVSS 9.1EG 9.12026-07-03
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
- CVE-2026-8927CRITICALCVSS 9.1EG 9.12026-07-03
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against …
- CVE-2021-27289CRITICALCVSS 9.1EG 9.12025-04-15
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame count…
- CVE-2025-26201CRITICALCVSS 9.1EG 9.12025-02-24
Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.
- CVE-2020-6972CRITICALCVSS 9.1EG 9.12020-03-24
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
- CVE-2019-9659CRITICALCVSS 9.1EG 9.12019-03-11
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango …
- CVE-2018-17903CRITICALCVSS 9.1EG 9.12018-10-24
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
- CVE-2026-28787CRITICALCVSS 9.0EG 9.02026-03-06
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does not store the challenge on the server side. Instead, the challenge is returned to the client…
- CVE-2026-69676HIGHCVSS 8.8EG 8.82026-09-08
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.
- CVE-2026-73431HIGHCVSS 8.8EG 8.82026-08-12
Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the user's login. Although th…
- CVE-2025-36593HIGHCVSS 8.8EG 8.82025-06-30
Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access could potentially exploit this vulnerability to fo…
Map vulnerabilities like CWE-294 to your infrastructure
EchelonGraph correlates every CVE — across CWE-294 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →