CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 12 of 16
- CVE-2023-5872MEDIUMCVSS 4.3EG 4.32026-04-16
In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.
- CVE-2023-5981HIGHCVSS 5.9EG 7.42023-11-28
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
- CVE-2023-5992MEDIUMCVSS 5.6EG 5.62024-01-31
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
- CVE-2023-6135MEDIUMCVSS 4.3EG 4.32023-12-19
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
- CVE-2023-6240MEDIUMCVSS 6.5EG 6.52024-02-04
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
- CVE-2023-6258HIGHCVSS 8.1EG 8.12024-01-30
A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, p…
- CVE-2023-6935MEDIUMCVSS 5.9EG 5.92024-02-09
wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configure: --enable-all CFLAGS="-DWOLFSSL_STATIC_RSA" The define �…
- CVE-2024-0202MEDIUMCVSS 5.9EG 5.92024-02-05
A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the tim…
- CVE-2024-0436HIGHCVSS 5.9EG 7.12024-02-26
Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by …
- CVE-2024-0553HIGHCVSS 7.5EG 7.52024-01-16
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform…
- CVE-2024-0564MEDIUMCVSS 5.3EG 5.32024-01-30
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the…
- CVE-2024-0914MEDIUMCVSS 5.9EG 5.92024-01-31
A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without acc…
- CVE-2024-10463HIGHCVSS 6.5EG 7.52024-10-29
Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
- CVE-2024-10929MEDIUMCVSS 5.1EG 5.12025-01-22
In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.
- CVE-2024-11084MEDIUMCVSS 6.3EG 6.32025-04-15
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
- CVE-2024-11159MEDIUMCVSS 4.3EG 4.32024-11-13
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.
- CVE-2024-11297MEDIUMCVSS 5.3EG 5.32024-12-20
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible fo…
- CVE-2024-12663LOWCVSS 3.7EG 3.72024-12-16
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable respo…
- CVE-2024-13028LOWCVSS 3.7EG 3.72024-12-29
A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to observable response…
- CVE-2024-13198LOWCVSS 3.7EG 3.72025-01-09
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack…
- CVE-2024-13939HIGHCVSS 7.5EG 7.52025-03-28
String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equa…
- CVE-2024-1543MEDIUMCVSS 4.1EG 4.12024-08-29
The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub…
- CVE-2024-1544MEDIUMCVSS 4.1EG 4.12024-08-27
Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k = r mod n. The division used during the reduction estimates a…
- CVE-2024-21206MEDIUMCVSS 4.3EG 4.32024-10-15
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attack…
- CVE-2024-21208LOWCVSS 3.7EG 3.72024-10-15
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12…
- CVE-2024-21210LOWCVSS 3.7EG 3.72024-10-15
Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4 and 23. Difficult to exploit vulnerability allows unauthenticated attacker with ne…
- CVE-2024-21233MEDIUMCVSS 4.3EG 4.32024-10-15
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create S…
- CVE-2024-21251LOWCVSS 3.1EG 3.12024-10-15
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Cre…
- CVE-2024-21484MEDIUMCVSS 5.9EG 5.92024-01-22
Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnera…
- CVE-2024-21671LOWCVSS 3.7EG 3.72024-01-30
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could …
- CVE-2024-22647MEDIUMCVSS 5.3EG 5.32024-01-30
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force …
- CVE-2024-23170MEDIUMCVSS 5.5EG 5.52024-01-31
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the att…
- CVE-2024-23218MEDIUMCVSS 5.9EG 5.92024-01-23
A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, m…
- CVE-2024-23342HIGHCVSS 7.4EG 7.42024-01-23
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve D…
- CVE-2024-23771CRITICALCVSS 9.8EG 9.82024-01-22
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.
- CVE-2024-23984MEDIUMCVSS 5.3EG 5.32024-09-16
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2024-2408MEDIUMCVSS 5.9EG 5.92024-06-09
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull requ…
- CVE-2024-2464MEDIUMCVSS 6.3EG 6.32024-03-21
This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions throug…
- CVE-2024-24766MEDIUMCVSS 6.2EG 6.22024-03-06
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enume…
- CVE-2024-25146MEDIUMCVSS 5.3EG 5.32024-02-08
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exi…
- CVE-2024-25189CRITICALCVSS 9.8EG 9.82024-02-08
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
- CVE-2024-25190CRITICALCVSS 9.8EG 9.82024-02-08
l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
- CVE-2024-25191CRITICALCVSS 9.8EG 9.82024-02-08
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
- CVE-2024-25651MEDIUMCVSS 5.3EG 5.32024-03-14
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.
- CVE-2024-25714CRITICALCVSS 9.8EG 9.82024-02-11
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_mem…
- CVE-2024-26221HIGHCVSS 7.2EG 7.22024-04-09
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2024-26268MEDIUMCVSS 5.3EG 5.32024-02-20
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attack…
- CVE-2024-27839MEDIUMCVSS 3.3EG 5.52024-05-14
A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.
- CVE-2024-28868LOWCVSS 3.7EG 3.72024-03-20
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disabl…
- CVE-2024-28885MEDIUMCVSS 5.9EG 5.92024-11-13
Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →