CWE-208

Observable Timing Discrepancy

Parent: CWE-203 - Observable Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

119 vulnerabilities with CWE-208
CVE-2024-21671 LOW
vantage6 <4.2.0 - Info Disclosure
CVSS 3.7
CVE-2024-23342 HIGH
ecdsa <0.18.0 - Info Disclosure
CVSS 7.4
CVE-2023-41313 CRITICAL
Apache Doris <2.0.0 - Info Disclosure
CVSS 9.8
CVE-2023-41097 MEDIUM
Silabs GSDK <4.4.0 - Crypto Attack
CVSS 4.6
CVE-2023-5981 MEDIUM
Gnutls - Information Disclosure
CVSS 5.9
CVE-2023-25529 HIGH
Nvidia Dgx H100 Firmware < 23.08.18 - Information Disclosure
CVSS 8.0
CVE-2023-40182 LOW
Silverware Games <1.3.6 - Info Disclosure
CVSS 3.7
CVE-2023-40021 MEDIUM
Oppia < 3.3.2 - CSRF
CVSS 5.3
CVE-2023-32694 MEDIUM
Saleor Core <3.7.67 - Timing Attack
CVSS 4.8
CVE-2023-25000 MEDIUM
HashiCorp Vault <1.13.1-1.12.5-1.11.9 - Info Disclosure
CVSS 5.0
CVE-2023-1538 MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2023-25806 MEDIUM
OpenSearch Security - Info Disclosure
CVSS 5.3
CVE-2022-25332 MEDIUM
Texas Instruments OMAP L138 - Timing Side Channel
CVSS 4.4
CVE-2022-42288 MEDIUM
Nvidia Dgx A100 Firmware < 00.19.07 - Information Disclosure
CVSS 5.3
CVE-2022-4823 LOW
InSTEDD Nuntium - Timing Discrepancy
CVSS 3.1
CVE-2022-39308 MEDIUM
GoCD <19.10.0 - Info Disclosure
CVSS 6.5
CVE-2022-31142 HIGH
@fastify/bearer-auth <7.0.2-8.0.1 - Info Disclosure
CVSS 7.5
CVE-2022-20752 MEDIUM
Cisco Unified CM - Timing Attack
CVSS 5.3
CVE-2022-29185 MEDIUM
totp-rs <1.1.0 - Info Disclosure
CVSS 4.2
CVE-2021-21575 MEDIUM
Dell BSAFE Micro Edition Suite <4.5.2 - Info Disclosure
CVSS 5.9
CVE-2021-34337 MEDIUM
Mailman Core <3.3.5 - Info Disclosure
CVSS 6.3
CVE-2021-4294 LOW
OpenShift OSIN - Timing Discrepancy
CVSS 2.6
CVE-2021-42016 HIGH
RUGGEDCOM - Path Traversal
CVSS 7.5
CVE-2021-43298 CRITICAL
HTTP Basic Auth - Brute Force
CVSS 9.8
CVE-2021-26318 MEDIUM
AMD CPU - Info Disclosure
CVSS 4.7
Details
Vulnerabilities 119