VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 12 of 40
  • CVE-2021-29443MedApr 16, 2021
    risk 0.38cvss 5.9epss 0.01

    jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed…

  • CVE-2020-1685MedOct 16, 2020
    risk 0.38cvss 5.8epss 0.01

    When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall filter configuration similar to: family…

  • CVE-2020-5929MedSep 25, 2020
    risk 0.38cvss 5.9epss 0.01

    In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) Diffie-Hellman key exchange and Single DH…

  • CVE-2015-8313MedDec 20, 2019
    risk 0.38cvss 5.9epss 0.02

    GnuTLS incorrectly validates the first byte of padding in CBC modes

  • CVE-2019-13629MedOct 3, 2019
    risk 0.38cvss 5.9epss 0.01

    MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because…

  • CVE-2019-13420MedAug 13, 2019
    risk 0.38cvss 5.9epss 0.01

    Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.

  • CVE-2019-10848MedMay 24, 2019
    risk 0.38cvss 5.3epss 0.08

    Computrols CBAS 18.0.0 allows Username Enumeration.

  • CVE-2018-9194MedSep 5, 2018
    risk 0.38cvss 5.9epss 0.01

    A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when…

  • CVE-2018-9192MedSep 5, 2018
    risk 0.38cvss 5.9epss 0.01

    A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection…

  • CVE-2017-18268MedMay 17, 2018
    risk 0.38cvss 5.9epss 0.02

    Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the…

  • CVE-2020-27211MedMay 21, 2021
    risk 0.37cvss 5.7epss 0.00

    Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.

  • CVE-2018-16869MedDec 3, 2018
    risk 0.37cvss 5.7epss 0.01

    A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext…

  • CVE-2018-3620MedAug 14, 2018
    risk 0.37cvss 5.6epss 0.06

    Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

  • CVE-2018-3640MedMay 22, 2018
    risk 0.37cvss 5.6epss 0.08

    Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE),…

  • CVE-2025-48561MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-21336MedJan 14, 2025
    risk 0.36cvss 5.6epss 0.01

    Windows Cryptographic Information Disclosure Vulnerability

  • CVE-2024-47155MedDec 26, 2024
    risk 0.36cvss 5.5epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-47154MedDec 26, 2024
    risk 0.36cvss 5.5epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-54476MedDec 12, 2024
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.

  • CVE-2024-50102MedNov 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: x86: fix user address masking non-canonical speculation issue It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical accesses in kernel space. And so using just the high bit to decide…