CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 5 of 17
- CVE-2020-6400MEDIUMCVSS 6.5EG 6.52020-02-11
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2014-9720MEDIUMCVSS 6.5EG 6.52020-01-24
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted re…
- CVE-2019-13456MEDIUMCVSS 6.5EG 6.52019-12-03
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to rec…
- CVE-2019-3740MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recov…
- CVE-2019-3739MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recove…
- CVE-2019-13140MEDIUMCVSS 6.5EG 6.52019-09-16
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by …
- CVE-2018-10919MEDIUMCVSS 4.3EG 6.52018-08-22
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expr…
- CVE-2022-48220MEDIUMCVSS 6.4EG 6.42024-02-14
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these p…
- CVE-2026-78617MEDIUMCVSS 6.3EG 6.32026-08-27
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is ena…
- CVE-2024-11084MEDIUMCVSS 6.3EG 6.32025-04-15
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
- CVE-2024-2464MEDIUMCVSS 6.3EG 6.32024-03-21
This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions throug…
- CVE-2019-16782MEDIUMCVSS 6.3EG 6.32019-12-18
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the …
- CVE-2019-13627MEDIUMCVSS 6.3EG 6.32019-09-25
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
- CVE-2026-56888MEDIUMCVSS 6.2EG 6.22026-09-15
In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2024-8994MEDIUMCVSS 6.2EG 6.22024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-8993MEDIUMCVSS 6.2EG 6.22024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-47153MEDIUMCVSS 6.2EG 6.22024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-24766MEDIUMCVSS 6.2EG 6.22024-03-06
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enume…
- CVE-2022-0823MEDIUMCVSS 6.2EG 6.22022-06-09
An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.
- CVE-2022-1318MEDIUMCVSS 6.2EG 6.22022-04-20
Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would…
- CVE-2023-3139MEDIUMCVSS 6.1EG 6.12023-07-04
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
- CVE-2026-3579MEDIUMCVSS 5.9EG 5.92026-03-19
wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on operand values. This affects multiple SP math…
- CVE-2025-11443MEDIUMCVSS 5.9EG 5.92025-10-08
A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forgotten Password Handler. This manipulation causes information exposure through discrepancy.…
- CVE-2024-28885MEDIUMCVSS 5.9EG 5.92024-11-13
Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.
- CVE-2024-50383MEDIUMCVSS 5.9EG 5.92024-10-23
Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was …
- CVE-2024-50382MEDIUMCVSS 5.9EG 5.92024-10-23
Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LL…
- CVE-2024-2408MEDIUMCVSS 5.9EG 5.92024-06-09
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull requ…
- CVE-2024-30171MEDIUMCVSS 5.9EG 5.92024-05-14
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
- CVE-2023-6935MEDIUMCVSS 5.9EG 5.92024-02-09
wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configure: --enable-all CFLAGS="-DWOLFSSL_STATIC_RSA" The define �…
- CVE-2024-0202MEDIUMCVSS 5.9EG 5.92024-02-05
A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the tim…
- CVE-2021-21575MEDIUMCVSS 5.9EG 5.92024-02-02
Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2024-0914MEDIUMCVSS 5.9EG 5.92024-01-31
A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without acc…
- CVE-2024-23218MEDIUMCVSS 5.9EG 5.92024-01-23
A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, m…
- CVE-2024-21484MEDIUMCVSS 5.9EG 5.92024-01-22
Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnera…
- CVE-2023-52323MEDIUMCVSS 5.9EG 5.92024-01-05
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
- CVE-2023-46739MEDIUMCVSS 5.9EG 5.92024-01-03
CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could allow an untrusted attacker to steal user passwords by carrying out a timing a…
- CVE-2023-50979MEDIUMCVSS 5.9EG 5.92023-12-18
Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.
- CVE-2023-49092MEDIUMCVSS 5.9EG 5.92023-11-28
RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able t…
- CVE-2023-40343MEDIUMCVSS 5.9EG 5.92023-08-16
Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.
- CVE-2023-32691MEDIUMCVSS 5.9EG 5.92023-05-30
gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compar…
- CVE-2023-27870MEDIUMCVSS 5.9EG 5.92023-05-11
IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in progress. IBM X-Force ID: 249518.
- CVE-2020-12413MEDIUMCVSS 5.9EG 5.92023-02-16
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
- CVE-2022-4304MEDIUMCVSS 5.9EG 5.92023-02-08
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have t…
- CVE-2022-2891MEDIUMCVSS 5.9EG 5.92022-10-10
The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.
- CVE-2022-27221MEDIUMCVSS 5.9EG 5.92022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a stri…
- CVE-2021-38153MEDIUMCVSS 5.9EG 5.92021-09-22
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or high…
- CVE-2021-33880MEDIUMCVSS 5.9EG 5.92021-06-06
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password…
- CVE-2021-27342MEDIUMCVSS 5.9EG 5.92021-05-17
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel a…
- CVE-2021-29446MEDIUMCVSS 5.9EG 5.92021-04-16
jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC…
- CVE-2021-29445MEDIUMCVSS 5.9EG 5.92021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →