CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 6 of 17
- CVE-2021-29444MEDIUMCVSS 5.9EG 5.92021-04-16
jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC …
- CVE-2021-29443MEDIUMCVSS 5.9EG 5.92021-04-16
jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decr…
- CVE-2020-1926MEDIUMCVSS 5.9EG 5.92021-03-16
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
- CVE-2020-25657MEDIUMCVSS 5.9EG 5.92021-01-12
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerabilit…
- CVE-2020-15237MEDIUMCVSS 5.9EG 5.92020-10-05
In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a timing attack to guess the signature of the derivation URL. The problem has been fixed by comparing sent and calculated si…
- CVE-2020-5929MEDIUMCVSS 5.9EG 5.92020-09-25
In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) D…
- CVE-2020-14145MEDIUMCVSS 5.9EG 5.92020-06-29
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the …
- CVE-2020-14002MEDIUMCVSS 5.9EG 5.92020-06-29
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cac…
- CVE-2019-20399MEDIUMCVSS 5.9EG 5.92020-01-23
A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak information via a side-channel attack.
- CVE-2015-8313MEDIUMCVSS 5.9EG 5.92019-12-20
GnuTLS incorrectly validates the first byte of padding in CBC modes
- CVE-2015-0837MEDIUMCVSS 5.9EG 5.92019-11-29
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last…
- CVE-2019-16863MEDIUMCVSS 5.9EG 5.92019-11-14
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
- CVE-2019-13629MEDIUMCVSS 5.9EG 5.92019-10-03
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key use…
- CVE-2019-13377MEDIUMCVSS 5.9EG 5.92019-08-15
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker …
- CVE-2019-13420MEDIUMCVSS 5.9EG 5.92019-08-13
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
- CVE-2019-11578MEDIUMCVSS 5.9EG 5.92019-04-28
auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.
- CVE-2019-9494MEDIUMCVSS 5.9EG 5.92019-04-17
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel …
- CVE-2019-1559MEDIUMCVSS 5.9EG 5.92019-02-27
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received w…
- CVE-2018-9194MEDIUMCVSS 5.9EG 5.92018-09-05
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable b…
- CVE-2018-9192MEDIUMCVSS 5.9EG 5.92018-09-05
A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable b…
- CVE-2017-18268MEDIUMCVSS 5.9EG 5.92018-05-17
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL co…
- CVE-2017-15533MEDIUMCVSS 5.9EG 5.92018-05-17
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the …
- CVE-2018-1000119MEDIUMCVSS 5.9EG 5.92018-03-07
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity …
- CVE-2017-12373MEDIUMCVSS 5.9EG 5.92017-12-15
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbach…
- CVE-2017-17427MEDIUMCVSS 5.9EG 5.92017-12-13
Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack"). This allows an attacker to decrypt observed traffic that has been encrypted with the…
- CVE-2017-13099MEDIUMCVSS 5.9EG 5.92017-12-13
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is refe…
- CVE-2017-13098MEDIUMCVSS 5.9EG 5.92017-12-13
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An att…
- CVE-2017-1000385MEDIUMCVSS 5.9EG 5.92017-12-12
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Blei…
- CVE-2016-0762MEDIUMCVSS 5.9EG 5.92017-08-10
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a t…
- CVE-2022-4823MEDIUMCVSS 3.1EG 5.92022-12-28
A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipulation of the argument signature leads to observable timing di…
- CVE-2026-73630MEDIUMCVSS 5.8EG 5.82026-08-14
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The endpoint never sets a failure code, so its…
- CVE-2025-47872MEDIUMCVSS 5.8EG 5.82025-08-08
The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numb…
- CVE-2025-29780MEDIUMCVSS 5.8EG 5.82025-03-14
Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `feldman_vss` library contains timing side-channel vulnerabili…
- CVE-2020-1685MEDIUMCVSS 5.8EG 5.82020-10-16
When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall fi…
- CVE-2020-27211MEDIUMCVSS 5.7EG 5.72021-05-21
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
- CVE-2018-16869MEDIUMCVSS 5.7EG 5.72018-12-03
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim proces…
- CVE-2025-21336MEDIUMCVSS 5.6EG 5.62025-01-14
Windows Cryptographic Information Disclosure Vulnerability
- CVE-2024-43546MEDIUMCVSS 5.6EG 5.62024-10-08
Windows Cryptographic Information Disclosure Vulnerability
- CVE-2023-5992MEDIUMCVSS 5.6EG 5.62024-01-31
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
- CVE-2023-1998MEDIUMCVSS 5.6EG 5.62023-04-21
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud prov…
- CVE-2018-16868MEDIUMCVSS 5.6EG 5.62018-12-03
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, coul…
- CVE-2018-3620MEDIUMCVSS 5.6EG 5.62018-08-14
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side…
- CVE-2018-3640MEDIUMCVSS 5.6EG 5.62018-05-22
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, a…
- CVE-2026-4040MEDIUMCVSS 5.5EG 5.52026-03-12
A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs t…
- CVE-2025-48561MEDIUMCVSS 5.5EG 5.52025-09-04
In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interact…
- CVE-2024-49733MEDIUMCVSS 5.5EG 5.52025-01-21
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges need…
- CVE-2024-47155MEDIUMCVSS 5.5EG 5.52024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-47154MEDIUMCVSS 5.5EG 5.52024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-54476MEDIUMCVSS 5.5EG 5.52024-12-12
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.
- CVE-2020-10369MEDIUMCVSS 5.5EG 5.52024-11-10
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack.
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →