CWE-294— Authentication Bypass by Capture-replay
166 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-294page 2 of 4
- CVE-2020-6972CRITICALCVSS 9.1EG 9.12020-03-24
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
- CVE-2020-9438MEDIUMCVSS 5.9EG 5.92020-06-23
Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.
- CVE-2021-22267MEDIUMCVSS 5.9EG 5.92021-02-09
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) …
- CVE-2021-22640HIGHCVSS 7.5EG 9.82022-07-28
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
- CVE-2021-25480MEDIUMCVSS 4.4EG 4.42021-10-06
A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.
- CVE-2021-25834HIGHCVSS 7.5EG 7.52021-02-08
Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application.
- CVE-2021-25835HIGHCVSS 7.5EG 7.52021-02-08
Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in e…
- CVE-2021-26824HIGHCVSS 7.1EG 7.12021-07-26
DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing local attackers to bypass user authentication and access all features and data on the USB.
- CVE-2021-27195MEDIUMCVSS 5.9EG 5.92021-03-25
Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.
- CVE-2021-27572HIGHCVSS 8.1EG 8.12021-05-07
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are set.
- CVE-2021-27662HIGHCVSS 8.6EG 8.62021-09-15
The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01
- CVE-2021-31958HIGHCVSS 7.5EG 8.82021-06-08
Windows NTLM Elevation of Privilege Vulnerability
- CVE-2021-35067HIGHCVSS 8.1EG 8.12021-10-07
Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message).
- CVE-2021-38296HIGHCVSS 7.5EG 7.52022-03-10
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key…
- CVE-2021-38459HIGHCVSS 8.1EG 8.12021-10-22
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/client connections. …
- CVE-2021-38827HIGHCVSS 7.5EG 7.52022-11-14
Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.
- CVE-2021-39364HIGHCVSS 7.5EG 7.52022-02-24
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.
- CVE-2021-40170MEDIUMCVSS 6.8EG 6.82021-12-15
An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30.20181117, allows an attacker to trigger arbitrary system functionality by replaying previously recorded signals. This …
- CVE-2021-41030MEDIUMCVSS 5.4EG 5.42021-12-08
An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAM…
- CVE-2021-46145MEDIUMCVSS 5.3EG 5.32022-01-06
The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization.
- CVE-2021-46835MEDIUMCVSS 4.3EG 4.32022-09-20
There is a traffic hijacking vulnerability in WS7200-10 11.0.2.13. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers.
- CVE-2022-2226MEDIUMCVSS 6.5EG 6.52022-12-22
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn…
- CVE-2022-22806CRITICALCVSS 9.8EG 9.82022-03-09
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: U…
- CVE-2022-22936HIGHCVSS 8.8EG 8.82022-03-29
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run ol…
- CVE-2022-25155HIGHCVSS 8.1EG 8.12022-04-01
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R se…
- CVE-2022-25159HIGHCVSS 8.1EG 8.12022-04-01
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU al…
- CVE-2022-25836HIGHCVSS 7.5EG 7.52022-12-12
Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with th…
- CVE-2022-25837HIGHCVSS 7.5EG 7.52022-12-12
Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairi…
- CVE-2022-25838HIGHCVSS 8.1EG 8.12022-02-24
Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.
- CVE-2022-27254MEDIUMCVSS 5.3EG 5.32022-03-23
The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.
- CVE-2022-2780HIGHCVSS 8.1EG 8.12022-10-14
In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.
- CVE-2022-29334CRITICALCVSS 9.8EG 9.82022-05-24
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
- CVE-2022-29475HIGHCVSS 8.1EG 8.12022-10-25
An information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can p…
- CVE-2022-29593MEDIUMCVSS 5.9EG 5.92022-07-14
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.
- CVE-2022-29878HIGHCVSS 7.5EG 8.12022-05-20
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a va…
- CVE-2022-30466MEDIUMCVSS 6.5EG 6.52022-06-07
joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay.
- CVE-2022-30467MEDIUMCVSS 6.8EG 6.82022-06-29
Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF.
- CVE-2022-31158HIGHCVSS 7.5EG 7.52022-07-15
LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. Users should u…
- CVE-2022-31265HIGHCVSS 8.8EG 8.82022-05-26
The replay feature in the client in Wargaming World of Warships 0.11.4 allows remote attackers to execute code when a user launches a replay from an untrusted source.
- CVE-2022-31277HIGHCVSS 8.8EG 8.82022-06-16
Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.
- CVE-2022-33208HIGHCVSS 8.1EG 8.12022-07-04
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1…
- CVE-2022-33971HIGHCVSS 7.5EG 7.52022-07-04
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller…
- CVE-2022-34151HIGHCVSS 8.1EG 8.12022-07-04
Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series al…
- CVE-2022-36089HIGHCVSS 8.2EG 8.22022-09-07
KubeVela is an application delivery platform Users using KubeVela's VelaUX APIServer could be affected by an authentication bypass vulnerability. In KubeVela prior to versions 1.4.11 and 1.5.4, VelaUX APIServer uses the `PlatformID` as the…
- CVE-2022-36945MEDIUMCVSS 6.4EG 6.42022-08-24
The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform unlock operations and force a resynchronization after capturing three consecutive valid key-fob signals over the radio,…
- CVE-2022-37011CRITICALCVSS 9.8EG 9.82022-09-13
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 9 compatible, New Track) (All versions < V3.3.1), Mendix SAML…
- CVE-2022-37305MEDIUMCVSS 6.4EG 6.42022-08-24
The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations and force a resynchronization after capturing five consecutive valid RKE signals over the radio, aka …
- CVE-2022-37418MEDIUMCVSS 6.4EG 6.42022-08-24
The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote attackers to perform unlock operations and force a resynchronization after capturing two consecutive valid key fob signal…
- CVE-2022-38766HIGHCVSS 8.1EG 8.12023-01-03
The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open request, which allows for a replay attack.
- CVE-2022-40621HIGHCVSS 7.5EG 7.52022-09-13
Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacke…
Map vulnerabilities like CWE-294 to your infrastructure
EchelonGraph correlates every CVE — across CWE-294 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →