VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 3 of 39
  • CVE-2025-21510HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-54767HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.02

    An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an…

  • CVE-2018-9364HigNov 19, 2024
    risk 0.49cvss 7.5epss 0.00

    In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.

  • CVE-2024-51739HigNov 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This…

  • CVE-2024-40490HigNov 1, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot Password function.

  • CVE-2024-39921HigSep 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may…

  • CVE-2022-45177HigFeb 21, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web…

  • CVE-2023-50782HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

  • CVE-2023-50781HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

  • CVE-2024-0553HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the…

  • CVE-2023-45287HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may…

  • CVE-2023-36127HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-33850HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain…

  • CVE-2023-34669HigJul 17, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

  • CVE-2023-34878HigJun 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/download-zip.

  • CVE-2023-1707HigJun 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.

  • CVE-2023-33741HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Macrovideo v380pro v1.4.97 shares the device id and password when sharing the device.

  • CVE-2023-32342HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain…

  • CVE-2023-1696HigMay 20, 2023
    risk 0.49cvss 7.5epss 0.00

    The multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-26557HigApr 21, 2023
    risk 0.49cvss 7.5epss 0.01

    io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modular exponentiation, or modular inverse. An example leak is in crypto/paillier/paillier.go.…