目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-294 使用捕获-重放进行的认证绕过 类漏洞列表 114

CWE-294 使用捕获-重放进行的认证绕过 类弱点 114 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-294 属于认证绕过漏洞,指攻击者通过嗅探网络流量,捕获认证数据包并重新发送给服务器,从而伪装成合法用户。此类攻击常见且难以防御,通常利用未加密或完整性校验不足的通信协议。开发者应通过实施强加密机制(如 TLS)、引入时间戳或随机数(Nonce)以及使用一次性令牌,确保每次请求的唯一性,从而有效防止重放攻击。

MITRE CWE 官方描述
CWE:CWE-294 通过捕获重放(Capture-replay)绕过身份验证 当产品的设计使得恶意用户能够嗅探网络流量,并通过将其重放(Replay)到目标服务器,从而产生与原始消息相同(或经过微小修改)的效果,以此绕过身份验证时,就存在捕获重放(Capture-replay)缺陷。 捕获重放(Capture-replay)攻击很常见,若没有密码学(Cryptography)的支持,往往难以抵御。它们是网络注入(Network Injection)攻击的一个子集,依赖于观察先前发送的有效命令,然后在必要时对其进行轻微修改,并重新向服务器发送这些命令。
常见影响 (1)
Access ControlGain Privileges or Assume Identity
Messages sent with a capture-relay attack allow access to resources which are not otherwise accessible without proper authentication.
缓解措施 (2)
Architecture and DesignUtilize some sequence or time stamping functionality along with a checksum which takes this into account in order to ensure that messages can be parsed only once.
Architecture and DesignSince any attacker who can listen to traffic can see sequence numbers, it is necessary to sign messages with some kind of cryptography to ensure that sequence numbers are not simply doctored along with content.
CVE ID标题CVSS风险等级Published
CVE-2024-43099 AutomationDirect DirectLogic H2-DM1E 安全漏洞 — DirectLogic H2-DM1E 8.8 High2024-09-13
CVE-2024-8260 Open Policy Agent 安全漏洞 — OPA 6.1 Medium2024-08-30
CVE-2024-3982 Hitachi Energy MicroSCADA X SYS600 安全漏洞 — MicroSCADA SYS600 8.2 High2024-08-27
CVE-2024-5249 Akana API Platform 安全漏洞 — Akana API Platform 5.4 Medium2024-07-30
CVE-2024-38438 D-Link DSL-225 安全漏洞 — DSL-225 9.8 Critical2024-07-21
CVE-2024-38272 Google Nearby 安全漏洞 — Nearby 7.5AIHighAI2024-06-26
CVE-2024-38284 Motorola Solutions Vigilant Fixed LPR Coms Box 安全漏洞 — Vigilant Fixed LPR Coms Box (BCAV1F2-C600) 9.1AICriticalAI2024-06-13
CVE-2024-34065 Strapi 安全漏洞 — strapi 7.1 High2024-06-12
CVE-2024-29901 AuthKit Next.js Library 安全漏洞 — authkit-nextjs 4.8 Medium2024-03-29
CVE-2023-6374 Mitsubishi Electric MELSEC WS Series 安全漏洞 — MELSEC WS Series WS0-GETH00200 5.9 Medium2024-01-30
CVE-2023-39547 NEC Corporation CLUSTERPRO 安全漏洞 — CLUSTERPRO X (EXPRESSCLUSTER X) 8.8 -2023-11-17
CVE-2023-45794 Siemens Mendix Applications 安全漏洞 — Mendix Applications using Mendix 10 6.8 Medium2023-11-14
CVE-2023-36857 Baker Hughes Bently Nevada 3500 安全漏洞 — Bently Nevada 3500 System 5.4 Medium2023-10-18
CVE-2023-39373 Hyundai Model 2017 安全漏洞 — model (2017) 7.4 High2023-09-03
CVE-2022-48507 Huawei HarmonyOS 安全漏洞 — HarmonyOS 7.5 -2023-07-06
CVE-2023-2846 Mitsubishi Electric MELSEC iQ-F series 安全漏洞 — MELSEC-F Series FX3U-16MR/ES 7.5 High2023-06-30
CVE-2023-29158 SUBNET PowerSYSTEM Center 安全漏洞 — PowerSYSTEM Center 6.1 Medium2023-06-19
CVE-2023-1886 phpMyFAQ 安全漏洞 — thorsten/phpmyfaq 7.3 High2023-04-05
CVE-2023-20123 Cisco Duo 安全漏洞 — Cisco Duo 6.3 Medium2023-04-05
CVE-2023-1537 answer 安全漏洞 — answerdev/answer 9.8 -2023-03-21
CVE-2022-45789 Schneider Electric EcoStruxure Control Expert 安全漏洞 — EcoStruxure Control Expert 8.1 High2023-01-31
CVE-2023-0014 SAP NetWeaver和SAP NetWeaver ABAP Server 安全漏洞 — NetWeaver ABAP Server and ABAP Platform 9.0 Critical2023-01-10
CVE-2022-44457 Siemens Mendix SAML Module 安全漏洞 — Mendix SAML (Mendix 7 compatible) 9.8 -2022-11-08
CVE-2022-29475 Abode Iota 信息泄露漏洞 — iota All-In-One Security Kit 8.1 -2022-10-25
CVE-2022-40621 WAVLINK WN531G3 安全漏洞 — WN531G3 8.1 -2022-09-13
CVE-2022-37011 Siemens Mendix SAML Module 安全漏洞 — Mendix SAML (Mendix 7 compatible) 9.8 -2022-09-13
CVE-2022-36089 KubeVela 安全漏洞 — kubevela 8.2 High2022-09-07
CVE-2022-31158 LTI 1.3 Tool Library 加密问题漏洞 — lti-1-3-php-library 7.5 High2022-07-15
CVE-2022-29878 Siemens SICAM 安全漏洞 — SICAM T 7.5 High2022-05-10
CVE-2021-38296 Apache Spark 加密问题漏洞 — Apache Spark 7.5 -2022-03-10

CWE-294(使用捕获-重放进行的认证绕过) 是常见的弱点类别,本平台收录该类弱点关联的 114 条 CVE 漏洞。