CWE-208

Observable Timing Discrepancy

Parent: CWE-203 - Observable Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

119 vulnerabilities with CWE-208
CVE-2024-36469 LOW
Zabbix 5.0.0 through 5.0.46 - Information Disclosure via Login Timing
CVSS 3.1
CVE-2024-13939 HIGH
Perl <0.322 - Timing Attack
CVSS 7.5
CVE-2024-22340 MEDIUM
IBM Common Cryptographic Architecture <7.5.51 - Info Disclosure
CVSS 6.5
CVE-2024-54772 MEDIUM
MikroTik RouterOS <7.17.2 - Info Disclosure
CVSS 5.4
CVE-2024-42512 HIGH
OPC UA .NET Standard Stack <1.5.374.158 - Auth Bypass
CVSS 8.6
CVE-2024-23953 MEDIUM
Apache Hive < 4.0.0 - Denial of Service
CVSS 6.5
CVE-2024-56738 MEDIUM
GNU GRUB <2.13 - Info Disclosure
CVSS 5.3
CVE-2024-52307 MEDIUM
authentik - Info Disclosure
CVSS 5.6
CVE-2024-31074 MEDIUM
Intel QAT Engine <v1.6.1 - Info Disclosure
CVSS 5.9
CVE-2024-41741 MEDIUM
IBM TXSeries for Multiplatforms 10.1 - Info Disclosure
CVSS 5.3
CVE-2024-7010 MEDIUM
mudler/localai <2.17.1 - Info Disclosure
CVSS 5.9
CVE-2024-47178 MEDIUM
basic-auth-connect <1.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-45052 MEDIUM
Fides <2.44.0 - Info Disclosure
CVSS 5.3
CVE-2024-1543 MEDIUM
wolfSSL <5.6.5 - Info Disclosure
CVSS 4.1
CVE-2024-45191 MEDIUM
Matrix libolm <3.2.16 - Cache Timing Attack
CVSS 5.3
CVE-2024-42368 MEDIUM
OpenTelemetry - Timing Attack
CVSS 6.5
CVE-2024-29995 HIGH
Windows Kerberos - Privilege Escalation
CVSS 8.1
CVE-2024-41828 LOW
JetBrains TeamCity <2024.07 - Info Disclosure
CVSS 2.6
CVE-2024-40640 LOW
vodozemac <0.7.0 - Info Disclosure
CVSS 2.9
CVE-2024-39329 MEDIUM
Django <5.0.7, <4.2.14 - Info Disclosure
CVSS 5.3
CVE-2024-36405 MEDIUM
liboqs - Timing Attack
CVSS 5.9
CVE-2024-2467 MEDIUM
perl-Crypt-OpenSSL-RSA - Info Disclosure
CVSS 5.9
CVE-2024-3296 MEDIUM
rust-openssl - Info Disclosure
CVSS 5.9
CVE-2024-24770 MEDIUM
vantage6 - Info Disclosure
CVSS 5.3
CVE-2024-0202 MEDIUM
cryptlib - Timing Attack
CVSS 5.9
Details
Vulnerabilities 119