VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 10 of 39
  • CVE-2019-13377MedAug 15, 2019
    risk 0.39cvss 5.9epss 0.02

    The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information…

  • CVE-2019-13383MedJul 16, 2019
    risk 0.39cvss 5.3epss 0.14

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.

  • CVE-2019-11578MedApr 28, 2019
    risk 0.39cvss 5.9epss 0.02

    auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.

  • CVE-2019-9494MedApr 17, 2019
    risk 0.39cvss 5.9epss 0.04

    The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full…

  • CVE-2017-15533MedMay 17, 2018
    risk 0.39cvss 5.9epss 0.02

    Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the oracle classification used in the ROBOT…

  • CVE-2026-47379MedJun 23, 2026
    risk 0.38cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back to strict-equality (===) comparison for legacy plaintext passwords, leaking the password's length and per-character prefix through response timing. This…

  • CVE-2025-47872MedAug 8, 2025
    risk 0.38cvss 5.8epss 0.00

    The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this…

  • CVE-2025-29780MedMar 14, 2025
    risk 0.38cvss epss 0.00

    Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `feldman_vss` library contains timing side-channel vulnerabilities in its matrix operations,…

  • CVE-2024-28885MedNov 13, 2024
    risk 0.38cvss 5.9epss 0.00

    Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.

  • CVE-2024-2408MedJun 9, 2024
    risk 0.38cvss 5.9epss 0.01

    The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: …

  • CVE-2023-6935MedFeb 9, 2024
    risk 0.38cvss 5.9epss 0.01

    wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configure: --enable-all CFLAGS="-DWOLFSSL_STATIC_RSA" The define “WOLFSSL_STATIC_RSA” enables static…

  • CVE-2024-0202MedFeb 5, 2024
    risk 0.38cvss 5.9epss 0.00

    A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the timing variant of the Bleichenbacher…

  • CVE-2021-21575MedFeb 2, 2024
    risk 0.38cvss 5.9epss 0.01

    Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

  • CVE-2024-0914MedJan 31, 2024
    risk 0.38cvss 5.9epss 0.01

    A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.

  • CVE-2024-23218MedJan 23, 2024
    risk 0.38cvss 5.9epss 0.01

    A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS…

  • CVE-2023-50979MedDec 18, 2023
    risk 0.38cvss 5.9epss 0.01

    Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.

  • CVE-2023-49092MedNov 28, 2023
    risk 0.38cvss 5.9epss 0.01

    RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the…

  • CVE-2023-5981MedNov 28, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

  • CVE-2023-40343MedAug 16, 2023
    risk 0.38cvss 5.9epss 0.00

    Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

  • CVE-2023-32691MedMay 30, 2023
    risk 0.38cvss 5.9epss 0.01

    gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compared directly with a secret. Since this…