Vulnerabilities > Authentication Bypass by Capture-replay

DATE CVE VULNERABILITY TITLE RISK
2023-06-30 CVE-2023-2846 Authentication Bypass by Capture-replay vulnerability in Mitsubishielectric products
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules allows a remote unauthenticated attacker to cancel the password/keyword setting and login to the affected products by sending specially crafted packets.
network
low complexity
mitsubishielectric CWE-294
critical
9.1
2023-06-22 CVE-2023-34553 Authentication Bypass by Capture-replay vulnerability in Wafucn Wafu Keyless Smart Lock Firmware 1.0
An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack.
low complexity
wafucn CWE-294
6.5
2023-06-13 CVE-2023-33621 Authentication Bypass by Capture-replay vulnerability in Gl-Inet Gl-Ar750S Firmware 3.215
GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded.
network
high complexity
gl-inet CWE-294
5.9
2023-05-24 CVE-2023-31759 Authentication Bypass by Capture-replay vulnerability in Keruistore Kerui W18 Firmware 1.0
Weak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack.
high complexity
keruistore CWE-294
7.5
2023-05-24 CVE-2023-31761 Authentication Bypass by Capture-replay vulnerability in Blitzwolf Bw-Is22 Firmware 1.0
Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
high complexity
blitzwolf CWE-294
7.5
2023-05-24 CVE-2023-31762 Authentication Bypass by Capture-replay vulnerability in Mydigoo Dg-Hamb Firmware 1.0
Weak security in the transmitter of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to gain full access to the system via a code replay attack.
high complexity
mydigoo CWE-294
7.5
2023-05-24 CVE-2023-31763 Authentication Bypass by Capture-replay vulnerability in Agshome Smart Alarm Project Agshome Smart Alarm Firmware 1.0
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
7.5
2023-05-22 CVE-2023-33281 Authentication Bypass by Capture-replay vulnerability in Nissan Sylphy Classic 2021 Firmware
The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack.
low complexity
nissan CWE-294
6.5
2023-04-21 CVE-2022-47930 Authentication Bypass by Capture-replay vulnerability in Iofinnet Tss-Lib
An issue was discovered in IO FinNet tss-lib before 2.0.0.
network
high complexity
iofinnet CWE-294
6.8
2023-04-05 CVE-2023-20123 Authentication Bypass by Capture-replay vulnerability in Cisco DUO and DUO Authentication for Windows Logon and RDP
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device.
low complexity
cisco CWE-294
4.6