VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 9 of 39
  • CVE-2024-11084MedApr 15, 2025
    risk 0.41cvss epss 0.00

    Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.

  • CVE-2024-2464MedMar 21, 2024
    risk 0.41cvss 6.3epss 0.00

    This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions through 5.7.1.

  • CVE-2023-51437HigFeb 7, 2024
    risk 0.41cvss 7.4epss 0.01

    Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. Users are recommended to upgrade to version 2.11.3, 3.0.2, or 3.1.1 which fixes the issue. Users…

  • CVE-2019-10764HigNov 18, 2019
    risk 0.41cvss 7.4epss 0.01

    In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an…

  • CVE-2019-13627MedSep 25, 2019
    risk 0.41cvss 6.3epss 0.01

    It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

  • CVE-2024-8994MedDec 26, 2024
    risk 0.40cvss 6.2epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-8993MedDec 26, 2024
    risk 0.40cvss 6.2epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-47153MedDec 26, 2024
    risk 0.40cvss 6.2epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2022-4304MedFeb 8, 2023
    risk 0.40cvss 5.9epss 0.16

    A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of…

  • CVE-2022-0823MedJun 9, 2022
    risk 0.40cvss 6.2epss 0.00

    An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.

  • CVE-2022-1318MedApr 20, 2022
    risk 0.40cvss 6.2epss 0.00

    Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would allow an attacker to learn the state of…

  • CVE-2021-45901MedFeb 10, 2022
    risk 0.39cvss 5.3epss 0.14

    The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

  • CVE-2021-44848MedDec 13, 2021
    risk 0.39cvss 5.3epss 0.23

    In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.

  • CVE-2021-38153MedSep 22, 2021
    risk 0.39cvss 5.9epss 0.06

    Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this…

  • CVE-2021-27342MedMay 17, 2021
    risk 0.39cvss 5.9epss 0.05

    An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack

  • CVE-2020-1926MedMar 16, 2021
    risk 0.39cvss 5.9epss 0.02

    Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8

  • CVE-2020-14002MedJun 29, 2020
    risk 0.39cvss 5.9epss 0.03

    PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).

  • CVE-2019-16516MedJan 23, 2020
    risk 0.39cvss 5.3epss 0.19

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.

  • CVE-2015-0837MedNov 29, 2019
    risk 0.39cvss 5.9epss 0.02

    The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

  • CVE-2019-16863MedNov 14, 2019
    risk 0.39cvss 5.9epss 0.03

    STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.