VYPR

CWE-385

Covert Timing Channel

BaseIncompleteLikelihood: Medium

Description

Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-462

CVEs mapped to this weakness (45)

page 3 of 3
  • CVE-2023-33855LowMar 26, 2024
    risk 0.24cvss 3.7epss 0.00

    Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: …

  • CVE-2024-13176MedJan 20, 2025
    risk 0.20cvss 4.1epss 0.01

    Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However,…

  • CVE-2020-14341LowJan 12, 2021
    risk 0.18cvss 2.7epss 0.01

    The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing…

  • CVE-2024-45192MedAug 22, 2024
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the…

  • CVE-2024-36405MedJun 10, 2024
    risk 0.00cvss 5.9epss 0.01

    liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference implementation of the Kyber key encapsulation mechanism when it is compiled with Clang 15-18 for…