VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 9 of 40
  • CVE-2021-21173MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.02

    Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6473MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-6400MedFeb 11, 2020
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-3739MedSep 18, 2019
    risk 0.42cvss 6.5epss 0.03

    RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.

  • CVE-2019-1020002HigJul 29, 2019
    risk 0.42cvss 7.5epss 0.01

    Pterodactyl before 0.7.14 with 2FA allows credential sniffing.

  • CVE-2017-12373MedDec 15, 2017
    risk 0.42cvss 5.9epss 0.13

    A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An…

  • CVE-2017-9735HigJun 16, 2017
    risk 0.42cvss 7.5epss 0.06

    Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

  • CVE-2016-2041HigFeb 20, 2016
    risk 0.42cvss 7.5epss 0.03

    libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time…

  • CVE-2026-78617MedAug 28, 2026
    risk 0.41cvss —epss 0.00

    WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked…

  • CVE-2024-11084MedApr 15, 2025
    risk 0.41cvss —epss 0.00

    Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.

  • CVE-2024-2464MedMar 21, 2024
    risk 0.41cvss 6.3epss 0.00

    This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions through 5.7.1.

  • CVE-2023-51437HigFeb 7, 2024
    risk 0.41cvss 7.4epss 0.01

    Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. Users are recommended to upgrade to version 2.11.3, 3.0.2, or 3.1.1 which fixes the issue. Users…

  • CVE-2019-10764HigNov 18, 2019
    risk 0.41cvss 7.4epss 0.01

    In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an…

  • CVE-2019-13627MedSep 25, 2019
    risk 0.41cvss 6.3epss 0.01

    It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.

  • CVE-2026-56888MedSep 15, 2026
    risk 0.40cvss 6.2epss 0.00

    In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-8994MedDec 26, 2024
    risk 0.40cvss 6.2epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-8993MedDec 26, 2024
    risk 0.40cvss 6.2epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-47153MedDec 26, 2024
    risk 0.40cvss 6.2epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2022-4304MedFeb 8, 2023
    risk 0.40cvss 5.9epss 0.16

    A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of…

  • CVE-2022-0823MedJun 9, 2022
    risk 0.40cvss 6.2epss 0.00

    An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.