Cyber Resilience

CWE · MITRE source

CWE-294Authentication Bypass by Capture-replay

Abstraction: Base · CVEs in our corpus: 256

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.

Last updated: 20 August 2026 20:22 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 11 mapping(s) from 2 framework(s): CAPEC 6 (partial) · ATT&CK 5 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-23 Session Authenticity
  • SC-40 Wireless Link Protection
  • SC-45 System Time Synchronization
  • AC-9 Previous Logon Notification
Detect
Catch it (CSF Detect / Respond)
  • DE.CM-01
Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V10.4.16
  • V10.5.1

NIST 800-53 r5 controls that address this weakness (4)AI-assisted

Control Title Family Why it addresses this CWE
SC-23Session AuthenticitySCProtects against replay of captured session tokens or credentials by requiring authenticated, fresh session channels.
SC-40Wireless Link ProtectionSCWireless link protections commonly incorporate replay protection, reducing the exploitability of capture-replay weaknesses.
SC-45System Time SynchronizationSCAccurate synchronized time enables tight timestamp windows that directly limit capture-replay windows in authentication protocols.
AC-9Previous Logon NotificationACAllows detection of capture-replay attacks by showing the replayed logon's timestamp as the last logon.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-23397 KEV 9.99.80.97412023-03-14
CVE-2017-3191 9.69.80.62532017-12-16
CVE-2023-49231 9.29.80.42902024-03-29
CVE-2022-22806 8.39.80.12262022-03-09
CVE-2017-6034 7.99.80.05182017-06-30
CVE-2018-7790 7.79.80.02482018-08-29
CVE-2019-18226 7.69.80.01372019-10-31
CVE-2018-17932 7.69.80.01512020-11-02
CVE-2018-19025 7.69.80.01512020-11-02
CVE-2022-29334 7.59.80.01222022-05-24
CVE-2022-37011 7.59.80.01122022-09-13
CVE-2023-30909 7.59.80.01062023-09-14
CVE-2025-497527.510.00.00912025-11-20
CVE-2017-6823 7.48.80.08042017-03-12
CVE-2017-11786 7.48.80.09392017-10-13
CVE-2022-44457 7.49.80.00722022-11-08
CVE-2023-1537 7.49.80.00842023-03-21
CVE-2023-47435 7.49.80.00632024-04-19
CVE-2024-38438 7.49.80.00662024-07-21
CVE-2026-118567.49.80.00602026-07-03
CVE-2020-35551 7.39.80.00422020-12-18
CVE-2026-285647.39.80.00442026-07-10
CVE-2026-680797.39.80.00412026-08-06
CVE-2018-17903 7.29.10.01562018-10-24
CVE-2025-65552 7.29.80.00362026-01-12