CWE-294— Authentication Bypass by Capture-replay
165 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-294page 1 of 4
- CVE-2013-1351MEDIUMCVSS 5.9EG 5.92020-01-30
Verax NMS prior to 2.10 allows authentication via the encrypted password without knowing the cleartext password.
- CVE-2017-5251HIGHCVSS 8.12018-02-22
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
- CVE-2018-1128HIGHCVSS 7.52018-07-10
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerabilit…
- CVE-2018-13789HIGHCVSS 7.52018-10-10
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
- CVE-2018-14781MEDIUMCVSS 5.32018-08-13
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless tran…
- CVE-2018-15498HIGHCVSS 8.1EG 8.12019-03-21
YSoft SafeQ Server 6 allows a replay attack.
- CVE-2018-16242MEDIUMCVSS 5.32018-09-14
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.
- CVE-2018-17176HIGHCVSS 7.52018-09-18
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. The…
- CVE-2018-17903CRITICALCVSS 9.12018-10-24
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
- CVE-2018-17932CRITICALCVSS 9.8EG 9.82020-11-02
JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, which could allow attackers to replay commands, control the device, view commands, or cause the device …
- CVE-2018-17935HIGHCVSS 8.12018-10-24
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the con…
- CVE-2018-19023HIGHCVSS 8.82019-01-25
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent…
- CVE-2018-19025CRITICALCVSS 9.8EG 9.82020-11-02
In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.).
- CVE-2018-7356MEDIUMCVSS 5.62018-11-01
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.
- CVE-2018-7790CRITICALCVSS 9.82018-08-29
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If…
- CVE-2018-9477HIGHCVSS 7.8EG 7.82024-11-20
In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte…
- CVE-2019-11334LOWCVSS 3.7EG 3.72019-06-11
An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-re…
- CVE-2019-11856LOWCVSS 3.3EG 3.32020-08-21
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.
- CVE-2019-12393HIGHCVSS 7.5EG 7.52019-12-02
Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.
- CVE-2019-12887HIGHCVSS 8.1EG 8.12019-06-27
KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2).
- CVE-2019-13533HIGHCVSS 8.1EG 8.12019-12-16
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.
- CVE-2019-18199MEDIUMCVSS 6.6EG 6.62019-10-24
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, and because of password-based authentication, they are vulnerable to replay attacks.
- CVE-2019-18226CRITICALCVSS 9.8EG 9.82019-10-31
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained…
- CVE-2019-20626MEDIUMCVSS 6.5EG 6.52020-03-23
The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might allow a replay attack.
- CVE-2019-3915HIGHCVSS 7.5EG 7.52019-04-11
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain acces…
- CVE-2019-5307MEDIUMCVSS 4.2EG 4.22019-06-04
Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better co…
- CVE-2019-9158MEDIUMCVSS 5.7EG 5.72019-06-05
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
- CVE-2019-9659CRITICALCVSS 9.1EG 9.12019-03-11
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango …
- CVE-2020-10045HIGHCVSS 8.8EG 8.82020-07-14
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error in the challenge-response procedure could allow an attacker to replay authentication traffic and ga…
- CVE-2020-10185HIGHCVSS 8.6EG 8.62020-03-05
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default con…
- CVE-2020-12355MEDIUMCVSS 6.8EG 6.82020-11-12
Authentication bypass by capture-replay in RPMB protocol message authentication subsystem in Intel(R) TXE versions before 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
- CVE-2020-12692MEDIUMCVSS 5.4EG 5.42020-05-07
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an …
- CVE-2020-13799MEDIUMCVSS 6.8EG 6.82020-11-18
Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for storage device interfaces, including all versions of eMMC, UFS, and NVMe. The RPMB protocol…
- CVE-2020-14302MEDIUMCVSS 4.9EG 4.92020-12-15
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allow…
- CVE-2020-15688HIGHCVSS 8.8EG 8.82020-07-23
The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote attacker to bypass authentication via capture-replay if TLS is not used to prot…
- CVE-2020-15931HIGHCVSS 7.5EG 7.52020-10-20
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a si…
- CVE-2020-23178MEDIUMCVSS 5.4EG 5.42021-07-02
An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.
- CVE-2020-24722MEDIUMCVSS 5.9EG 5.92020-10-07
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX value lacks a checksum, allowing bitflip…
- CVE-2020-25229HIGHCVSS 7.5EG 7.52020-12-14
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encryption for communication with affected devices is prone to replay attacks due to the usage of a static key. An attacker co…
- CVE-2020-25660HIGHCVSS 8.8EG 8.82020-11-23
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with acc…
- CVE-2020-26172MEDIUMCVSS 4.2EG 4.22020-12-18
Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp.
- CVE-2020-27157HIGHCVSS 8.1EG 8.12020-10-15
Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the …
- CVE-2020-27269MEDIUMCVSS 5.7EG 5.72021-01-19
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physic…
- CVE-2020-27374HIGHCVSS 7.5EG 7.52022-04-07
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.
- CVE-2020-28713MEDIUMCVSS 6.5EG 6.52021-06-08
Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote users to send push notification events via an exposed PNS server. A remote attacker can passively record push notification …
- CVE-2020-35473MEDIUMCVSS 4.3EG 4.32022-11-08
An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2, may be used to iden…
- CVE-2020-35551CRITICALCVSS 9.8EG 9.82020-12-18
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a relate…
- CVE-2020-4042MEDIUMCVSS 6.8EG 6.82020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious …
- CVE-2020-5261HIGHCVSS 8.2EG 8.22020-03-25
Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 has a faulty implementation of Token Replay Detection. Token Replay Detection is an important defence in depth measu…
- CVE-2020-5300MEDIUMCVSS 5.8EG 5.82020-04-06
In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authentication method 'private_key_jwt' [1], OpenId specification says the following about assertio…
Map vulnerabilities like CWE-294 to your infrastructure
EchelonGraph correlates every CVE — across CWE-294 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →