VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 11 of 40
  • CVE-2024-28885MedNov 13, 2024
    risk 0.38cvss 5.9epss 0.00

    Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.

  • CVE-2024-2408MedJun 9, 2024
    risk 0.38cvss 5.9epss 0.01

    The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: …

  • CVE-2023-6935MedFeb 9, 2024
    risk 0.38cvss 5.9epss 0.01

    wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configure: --enable-all CFLAGS="-DWOLFSSL_STATIC_RSA" The define “WOLFSSL_STATIC_RSA” enables static…

  • CVE-2024-0202MedFeb 5, 2024
    risk 0.38cvss 5.9epss 0.00

    A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the timing variant of the Bleichenbacher…

  • CVE-2021-21575MedFeb 2, 2024
    risk 0.38cvss 5.9epss 0.01

    Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

  • CVE-2024-0914MedJan 31, 2024
    risk 0.38cvss 5.9epss 0.01

    A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.

  • CVE-2024-23218MedJan 23, 2024
    risk 0.38cvss 5.9epss 0.01

    A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS…

  • CVE-2023-50979MedDec 18, 2023
    risk 0.38cvss 5.9epss 0.01

    Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.

  • CVE-2023-49092MedNov 28, 2023
    risk 0.38cvss 5.9epss 0.01

    RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the…

  • CVE-2023-5981MedNov 28, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

  • CVE-2023-40343MedAug 16, 2023
    risk 0.38cvss 5.9epss 0.01

    Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

  • CVE-2023-32691MedMay 30, 2023
    risk 0.38cvss 5.9epss 0.01

    gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compared directly with a secret. Since this…

  • CVE-2023-27870MedMay 11, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in progress. IBM X-Force ID: 249518.

  • CVE-2020-12413MedFeb 16, 2023
    risk 0.38cvss 5.9epss 0.01

    The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.

  • CVE-2022-2891MedOct 10, 2022
    risk 0.38cvss 5.9epss 0.01

    The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.

  • CVE-2022-27221MedJun 14, 2022
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially…

  • CVE-2020-15522MedMay 20, 2021
    risk 0.38cvss 5.9epss 0.02

    Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the…

  • CVE-2021-29446MedApr 16, 2021
    risk 0.38cvss 5.9epss 0.01

    jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if…

  • CVE-2021-29445MedApr 16, 2021
    risk 0.38cvss 5.9epss 0.01

    jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if…

  • CVE-2021-29444MedApr 16, 2021
    risk 0.38cvss 5.9epss 0.01

    jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if…