CWE-294— Authentication Bypass by Capture-replay
211 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-294page 4 of 5
- CVE-2024-34065HIGHCVSS 7.1EG 7.12024-06-12
Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unau…
- CVE-2024-36250LOWCVSS 3.1EG 3.12024-11-09
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
- CVE-2024-37016MEDIUMCVSS 6.8EG 6.82024-07-15
Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.
- CVE-2024-38272MEDIUMCVSS 4.3EG 4.32024-06-26
There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if …
- CVE-2024-38284HIGHCVSS 8.7EG 0.02024-06-13
Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.
- CVE-2024-38438CRITICALCVSS 9.8EG 9.82024-07-21
D-Link - CWE-294: Authentication Bypass by Capture-replay
- CVE-2024-38823LOWCVSS 2.7EG 2.72025-06-13
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
- CVE-2024-38890HIGHCVSS 8.4EG 8.42024-08-02
An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection a…
- CVE-2024-39081MEDIUMCVSS 4.2EG 4.22024-09-18
An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.
- CVE-2024-3982HIGHCVSS 8.2EG 8.22024-08-27
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logg…
- CVE-2024-4009CRITICALCVSS 9.2EG 9.22024-06-05
Replay Attack in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KNX Bus-System
- CVE-2024-40715HIGHCVSS 7.7EG 7.72024-11-07
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.
- CVE-2024-43099HIGHCVSS 8.8EG 8.82024-09-13
The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker…
- CVE-2024-45244MEDIUMCVSS 5.3EG 5.42024-08-25
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
- CVE-2024-46041HIGHCVSS 8.8EG 8.82024-10-07
IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.
- CVE-2024-49595HIGHCVSS 7.6EG 7.62024-11-26
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of serv…
- CVE-2024-5249MEDIUMCVSS 5.4EG 5.42024-07-30
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
- CVE-2024-52534MEDIUMCVSS 5.4EG 5.42024-12-25
Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
- CVE-2024-8260MEDIUMCVSS 6.1EG 6.12024-08-30
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an…
- CVE-2025-13777HIGHCVSS 8.3EG 8.32026-03-13
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.
- CVE-2025-1887HIGHCVSS 7.1EG 0.02025-03-07
SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC p…
- CVE-2025-26201CRITICALCVSS 9.1EG 9.12025-02-24
Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.
- CVE-2025-30072HIGHCVSS 7.6EG 7.62025-05-19
Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.
- CVE-2025-30201HIGHCVSS 7.7EG 7.72025-11-21
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths i…
- CVE-2025-35057MEDIUMCVSS 5.3EG 5.32025-10-09
Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the NIX servi…
- CVE-2025-35058MEDIUMCVSS 5.9EG 5.92025-10-09
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-…
- CVE-2025-35061MEDIUMCVSS 5.9EG 5.92025-10-09
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the…
- CVE-2025-36593HIGHCVSS 8.8EG 8.82025-06-30
Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access could potentially exploit this vulnerability to fo…
- CVE-2025-40807MEDIUMCVSS 6.3EG 6.32025-12-09
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could allow an authenticated but already locked-out user to establis…
- CVE-2025-46815HIGHCVSS 8.0EG 8.02025-05-06
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the cli…
- CVE-2025-47706MEDIUMCVSS 4.8EG 4.82025-05-14
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5…
- CVE-2025-48012MEDIUMCVSS 4.8EG 4.82025-05-21
Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0.
- CVE-2025-49752CRITICALCVSS 10.0EG 10.02025-11-20
Azure Bastion Elevation of Privilege Vulnerability
- CVE-2025-54810HIGHCVSS 8.0EG 8.02025-09-18
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as…
- CVE-2025-56448MEDIUMCVSS 6.8EG 6.82025-09-15
The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured…
- CVE-2025-59023HIGHCVSS 8.2EG 8.22026-02-09
Crafted delegations or IP fragments can poison cached delegations in Recursor.
- CVE-2025-6029CRITICALCVSS 9.4EG 0.02025-06-13
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack.…
- CVE-2025-6030CRITICALCVSS 9.4EG 0.02025-06-13
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA So…
- CVE-2025-64131HIGHCVSS 7.5EG 7.52025-10-29
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, aut…
- CVE-2025-6533MEDIUMCVSS 5.6EG 5.62025-06-24
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginContro…
- CVE-2025-65552CRITICALCVSS 9.8EG 9.82026-01-12
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attack…
- CVE-2025-65553MEDIUMCVSS 6.5EG 6.52026-01-12
D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attacker within RF range can transmit continuous interference to block sensor transmissions, resulting in missed alarms and …
- CVE-2025-67135CRITICALCVSS 9.8EG 9.82026-02-11
Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.
- CVE-2025-68671MEDIUMCVSS 6.5EG 6.52026-01-15
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a val…
- CVE-2025-69197MEDIUMCVSS 6.5EG 6.52026-01-06
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward…
- CVE-2025-69822HIGHCVSS 7.4EG 7.42026-01-22
An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame
- CVE-2025-8616MEDIUMCVSS 6.1EG 0.02025-08-06
A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0.
- CVE-2025-9100MEDIUMCVSS 5.3EG 5.32025-08-18
A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by c…
- CVE-2026-1743LOWCVSS 3.1EG 3.12026-02-02
A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass …
- CVE-2026-24027MEDIUMCVSS 5.3EG 5.32026-02-09
Crafted zones can lead to increased incoming network traffic.
Map vulnerabilities like CWE-294 to your infrastructure
EchelonGraph correlates every CVE — across CWE-294 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →