CWE-203
Observable Discrepancy
Description
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-189
CVEs mapped to this weakness (798)
page 12 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-29443 | Med | 0.38 | 5.9 | 0.01 | Apr 16, 2021 | jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed… | ||
| CVE-2020-1685 | Med | 0.38 | 5.8 | 0.01 | Oct 16, 2020 | When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall filter configuration similar to: family… | ||
| CVE-2020-5929 | Med | 0.38 | 5.9 | 0.01 | Sep 25, 2020 | In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) Diffie-Hellman key exchange and Single DH… | ||
| CVE-2015-8313 | Med | 0.38 | 5.9 | 0.02 | Dec 20, 2019 | GnuTLS incorrectly validates the first byte of padding in CBC modes | ||
| CVE-2019-13629 | Med | 0.38 | 5.9 | 0.01 | Oct 3, 2019 | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because… | ||
| CVE-2019-13420 | Med | 0.38 | 5.9 | 0.01 | Aug 13, 2019 | Search Guard versions before 21.0 had an timing side channel issue when using the internal user database. | ||
| CVE-2019-10848 | Med | 0.38 | 5.3 | 0.08 | May 24, 2019 | Computrols CBAS 18.0.0 allows Username Enumeration. | ||
| CVE-2018-9194 | Med | 0.38 | 5.9 | 0.01 | Sep 5, 2018 | A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when… | ||
| CVE-2018-9192 | Med | 0.38 | 5.9 | 0.01 | Sep 5, 2018 | A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection… | ||
| CVE-2017-18268 | Med | 0.38 | 5.9 | 0.02 | May 17, 2018 | Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the… | ||
| CVE-2020-27211 | Med | 0.37 | 5.7 | 0.00 | May 21, 2021 | Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase. | ||
| CVE-2018-16869 | Med | 0.37 | 5.7 | 0.01 | Dec 3, 2018 | A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext… | ||
| CVE-2018-3620 | Med | 0.37 | 5.6 | 0.06 | Aug 14, 2018 | Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis. | ||
| CVE-2018-3640 | Med | 0.37 | 5.6 | 0.08 | May 22, 2018 | Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE),… | ||
| CVE-2025-48561 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2025 | In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2025-21336 | Med | 0.36 | 5.6 | 0.01 | Jan 14, 2025 | Windows Cryptographic Information Disclosure Vulnerability | ||
| CVE-2024-47155 | Med | 0.36 | 5.5 | 0.00 | Dec 26, 2024 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | ||
| CVE-2024-47154 | Med | 0.36 | 5.5 | 0.00 | Dec 26, 2024 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | ||
| CVE-2024-54476 | Med | 0.36 | 5.5 | 0.00 | Dec 12, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data. | ||
| CVE-2024-50102 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: x86: fix user address masking non-canonical speculation issue It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical accesses in kernel space. And so using just the high bit to decide… |
- risk 0.38cvss 5.9epss 0.01
jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed…
- risk 0.38cvss 5.8epss 0.01
When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall filter configuration similar to: family…
- risk 0.38cvss 5.9epss 0.01
In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) Diffie-Hellman key exchange and Single DH…
- risk 0.38cvss 5.9epss 0.02
GnuTLS incorrectly validates the first byte of padding in CBC modes
- risk 0.38cvss 5.9epss 0.01
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because…
- risk 0.38cvss 5.9epss 0.01
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
- risk 0.38cvss 5.3epss 0.08
Computrols CBAS 18.0.0 allows Username Enumeration.
- risk 0.38cvss 5.9epss 0.01
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when…
- risk 0.38cvss 5.9epss 0.01
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection…
- risk 0.38cvss 5.9epss 0.02
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the…
- risk 0.37cvss 5.7epss 0.00
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
- risk 0.37cvss 5.7epss 0.01
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext…
- risk 0.37cvss 5.6epss 0.06
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.
- risk 0.37cvss 5.6epss 0.08
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE),…
- risk 0.36cvss 5.5epss 0.00
In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.6epss 0.01
Windows Cryptographic Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- risk 0.36cvss 5.5epss 0.00
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: x86: fix user address masking non-canonical speculation issue It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical accesses in kernel space. And so using just the high bit to decide…