CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
794 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 2 of 16
- CVE-2018-1000119MEDIUMCVSS 5.9EG 5.92018-03-07
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity …
- CVE-2018-1000884CRITICALCVSS 9.8EG 9.82018-12-20
Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure Through Timing Discrepancy vulnerability in Password reset code -- web/reset/index.php, li…
- CVE-2018-10919MEDIUMCVSS 4.3EG 6.52018-08-22
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expr…
- CVE-2018-10949MEDIUMCVSS 5.3EG 5.32018-05-10
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.
- CVE-2018-14597MEDIUMCVSS 5.3EG 5.32018-10-17
CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.
- CVE-2018-16868MEDIUMCVSS 5.6EG 5.62018-12-03
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, coul…
- CVE-2018-16869MEDIUMCVSS 5.7EG 5.72018-12-03
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim proces…
- CVE-2018-3615HIGHCVSS 7.3EG 7.32018-08-14
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user acce…
- CVE-2018-3620MEDIUMCVSS 5.6EG 5.62018-08-14
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side…
- CVE-2018-3639HIGHCVSS 5.5EG 7.42018-05-22
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local use…
- CVE-2018-3640MEDIUMCVSS 5.6EG 5.62018-05-22
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, a…
- CVE-2018-5407MEDIUMCVSS 4.7EG 4.72018-11-15
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
- CVE-2018-9192MEDIUMCVSS 5.9EG 5.92018-09-05
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable b…
- CVE-2018-9194MEDIUMCVSS 5.9EG 5.92018-09-05
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable b…
- CVE-2018-9364HIGHCVSS 7.5EG 7.52024-11-19
In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.
- CVE-2019-10071CRITICALCVSS 9.8EG 9.82019-09-16
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to deter…
- CVE-2019-10114HIGHCVSS 7.5EG 7.52019-05-16
An Information Exposure issue (issue 2 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. During the OAuth authentication process, the application attempts to vali…
- CVE-2019-1020002HIGHCVSS 7.5EG 7.52019-07-29
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
- CVE-2019-10233HIGHCVSS 8.1EG 8.12019-03-27
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
- CVE-2019-10483MEDIUMCVSS 5.5EG 5.52020-04-16
Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IO…
- CVE-2019-10764HIGHCVSS 7.4EG 7.42019-11-18
In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during s…
- CVE-2019-10848MEDIUMCVSS 5.3EG 5.32019-05-24
Computrols CBAS 18.0.0 allows Username Enumeration.
- CVE-2019-11465MEDIUMCVSS 5.3EG 5.32019-09-10
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the use…
- CVE-2019-11578MEDIUMCVSS 5.9EG 5.92019-04-28
auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.
- CVE-2019-11743LOWCVSS 3.7EG 3.72019-09-27
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in po…
- CVE-2019-12383MEDIUMCVSS 4.3EG 4.32019-05-28
Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.
- CVE-2019-12743MEDIUMCVSS 5.3EG 5.32019-07-29
HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response…
- CVE-2019-12953MEDIUMCVSS 5.3EG 5.32020-12-30
Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.
- CVE-2019-13140MEDIUMCVSS 6.5EG 6.52019-09-16
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by …
- CVE-2019-13377MEDIUMCVSS 5.9EG 5.92019-08-15
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker …
- CVE-2019-13383MEDIUMCVSS 5.3EG 5.32019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.
- CVE-2019-13420MEDIUMCVSS 5.9EG 5.92019-08-13
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
- CVE-2019-13456MEDIUMCVSS 6.5EG 6.52019-12-03
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to rec…
- CVE-2019-13599MEDIUMCVSS 5.3EG 5.32019-08-21
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.
- CVE-2019-13627MEDIUMCVSS 6.3EG 6.32019-09-25
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
- CVE-2019-13628MEDIUMCVSS 4.7EG 4.72019-10-03
wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to precisely measure the dur…
- CVE-2019-13629MEDIUMCVSS 5.9EG 5.92019-10-03
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key use…
- CVE-2019-13666HIGHCVSS 7.4EG 7.42019-11-25
Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2019-13684MEDIUMCVSS 5.3EG 5.32019-11-25
Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2019-14007MEDIUMCVSS 5.5EG 5.52020-04-16
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential side channel for SUI corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Co…
- CVE-2019-14067MEDIUMCVSS 5.5EG 5.52020-06-02
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channel issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
- CVE-2019-14353MEDIUMCVSS 4.2EG 4.22019-08-08
On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents…
- CVE-2019-14354LOWCVSS 2.4EG 2.42019-08-10
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display content…
- CVE-2019-14355LOWCVSS 2.4EG 2.42019-08-10
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For…
- CVE-2019-14356MEDIUMCVSS 5.3EG 5.32019-10-31
On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. F…
- CVE-2019-14357LOWCVSS 2.4EG 2.42019-08-10
On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For ex…
- CVE-2019-14358MEDIUMCVSS 4.6EG 4.62019-11-02
On Archos Safe-T devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For exam…
- CVE-2019-14359LOWCVSS 2.4EG 2.42019-08-12
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For e…
- CVE-2019-14360MEDIUMCVSS 4.6EG 4.62019-11-02
On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display conten…
- CVE-2019-15132MEDIUMCVSS 5.3EG 5.32019-08-17
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions fo…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →