Cyber Posture

CWE · MITRE source

CWE-294Authentication Bypass by Capture-replay

Abstraction: Base · CVEs in our corpus: 210

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (4)AI

Control Title Family Why it addresses this CWE
SC-23Session AuthenticitySCProtects against replay of captured session tokens or credentials by requiring authenticated, fresh session channels.
SC-40Wireless Link ProtectionSCWireless link protections commonly incorporate replay protection, reducing the exploitability of capture-replay weaknesses.
SC-45System Time SynchronizationSCAccurate synchronized time enables tight timestamp windows that directly limit capture-replay windows in authentication protocols.
AC-9Previous Logon NotificationACAllows detection of capture-replay attacks by showing the replayed logon's timestamp as the last logon.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-23397 KEV9.69.80.93402023-03-14
CVE-2017-31914.09.80.33802017-12-16
CVE-2017-117862.48.80.11492017-10-13
CVE-2023-309092.39.80.04962023-09-14
CVE-2017-68232.28.80.06842017-03-12
CVE-2017-60342.09.80.00132017-06-30
CVE-2018-77902.09.80.01132018-08-29
CVE-2019-182262.09.80.00182019-10-31
CVE-2018-179322.09.80.00242020-11-02
CVE-2018-190252.09.80.00242020-11-02
CVE-2020-355512.09.80.00132020-12-18
CVE-2022-228062.09.80.00232022-03-09
CVE-2022-293342.09.80.00332022-05-24
CVE-2022-370112.09.80.00912022-09-13
CVE-2022-444572.09.80.00462022-11-08
CVE-2023-15372.09.80.00262023-03-21
CVE-2023-492312.09.80.00832024-03-29
CVE-2023-474352.09.80.00082024-04-19
CVE-2024-384382.09.80.00212024-07-21
CVE-2025-497522.010.00.00072025-11-20
CVE-2025-655522.09.80.00132026-01-12
CVE-2025-671352.09.80.00022026-02-11
CVE-2026-307892.09.80.00172026-03-05
CVE-2026-329872.09.80.00062026-03-29
CVE-2025-262011.99.10.00522025-02-24