Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
137 vulnerabilities with CWE-208
CVE-2023-32694
MEDIUM
Saleor Core <3.7.67 - Timing Attack
CVSS 4.8
CVE-2023-25000
MEDIUM
HashiCorp Vault <1.13.1-1.12.5-1.11.9 - Info Disclosure
CVSS 5.0
CVE-2023-1538
MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2023-25806
MEDIUM
OpenSearch Security - Info Disclosure
CVSS 5.3
CVE-2022-25332
MEDIUM
Texas Instruments OMAP L138 - Timing Side Channel
CVSS 4.4
CVE-2022-42288
MEDIUM
NVIDIA DGX A100 Firmware < 00.19.07 - Unauthenticated Username Enumeration via IPMI Handler Timing Discrepancy
CVSS 5.3
CVE-2022-4823
LOW
InSTEDD Nuntium - Timing Discrepancy
CVSS 3.1
CVE-2022-39308
MEDIUM
GoCD 19.2.0-19.10.0 - Timing Attack via Access Token Validation
CVSS 6.5
CVE-2022-31142
HIGH
@fastify/bearer-auth <7.0.2-8.0.1 - Info Disclosure
CVSS 7.5
CVE-2022-20752
MEDIUM
Cisco Unified Communications Manager 12.5(1) - Observable Timing Discrepancy
CVSS 5.3
CVE-2022-29185
MEDIUM
totp-rs < 1.1.0 - Observable Timing Discrepancy in Token Comparison
CVSS 4.2
CVE-2021-21575
MEDIUM
Dell BSAFE Micro Edition Suite <4.5.2 - Info Disclosure
CVSS 5.9
CVE-2021-34337
MEDIUM
Mailman Core <3.3.5 - Info Disclosure
CVSS 6.3
CVE-2021-4294
LOW
OpenShift OSIN - Timing Discrepancy
CVSS 2.6
CVE-2021-42016
HIGH
Siemens RUGGEDCOM ROS - Observable Timing Discrepancy in Third-Party Component
CVSS 7.5
CVE-2021-43298
CRITICAL
GoAhead < 5.1.4 - Unauthenticated Password Brute-Force via Timing Attack
CVSS 9.8
CVE-2021-26318
MEDIUM
AMD Athlon, Athlon Pro, EPYC, Ryzen, and Ryzen Pro Firmware - Observable Timing Discrepancy via PREFETCH Instructions
CVSS 4.7
CVE-2021-26314
MEDIUM
Xen - Observable Timing Discrepancy via Floating Point Value Injection
CVSS 5.5
CVE-2021-26313
MEDIUM
Xen - Observable Timing Discrepancy via Speculative Code Store Bypass
CVSS 5.5
CVE-2021-31406
MEDIUM
Vaadin Flow 3.0.0-5.0.3 and Vaadin 15.0.0-18.0.6 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2021-31404
MEDIUM
Vaadin Flow 1.0.0-1.0.13 and Vaadin 10.0.0-10.0.16 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2021-31403
MEDIUM
Vaadin 7.0.0-7.7.23 and 8.0.0-8.12.2 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2020-35165
MEDIUM
Dell BSAFE <4.1.5-4.6 - Info Disclosure
CVSS 5.1
CVE-2020-1926
MEDIUM
Apache Hive <2.3.8 - Info Disclosure
CVSS 5.9
CVE-2020-15237
MEDIUM
Shrine < 3.3.0 - Observable Timing Discrepancy in Derivation Endpoint Signature Verification
CVSS 5.9
Details
Vulnerabilities
137