CWE-208

Observable Timing Discrepancy

Parent: CWE-203 - Observable Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

137 vulnerabilities with CWE-208
CVE-2023-32694 MEDIUM
Saleor Core <3.7.67 - Timing Attack
CVSS 4.8
CVE-2023-25000 MEDIUM
HashiCorp Vault <1.13.1-1.12.5-1.11.9 - Info Disclosure
CVSS 5.0
CVE-2023-1538 MEDIUM
answerdev/answer <1.0.6 - Info Disclosure
CVSS 5.3
CVE-2023-25806 MEDIUM
OpenSearch Security - Info Disclosure
CVSS 5.3
CVE-2022-25332 MEDIUM
Texas Instruments OMAP L138 - Timing Side Channel
CVSS 4.4
CVE-2022-42288 MEDIUM
NVIDIA DGX A100 Firmware < 00.19.07 - Unauthenticated Username Enumeration via IPMI Handler Timing Discrepancy
CVSS 5.3
CVE-2022-4823 LOW
InSTEDD Nuntium - Timing Discrepancy
CVSS 3.1
CVE-2022-39308 MEDIUM
GoCD 19.2.0-19.10.0 - Timing Attack via Access Token Validation
CVSS 6.5
CVE-2022-31142 HIGH
@fastify/bearer-auth <7.0.2-8.0.1 - Info Disclosure
CVSS 7.5
CVE-2022-20752 MEDIUM
Cisco Unified Communications Manager 12.5(1) - Observable Timing Discrepancy
CVSS 5.3
CVE-2022-29185 MEDIUM
totp-rs < 1.1.0 - Observable Timing Discrepancy in Token Comparison
CVSS 4.2
CVE-2021-21575 MEDIUM
Dell BSAFE Micro Edition Suite <4.5.2 - Info Disclosure
CVSS 5.9
CVE-2021-34337 MEDIUM
Mailman Core <3.3.5 - Info Disclosure
CVSS 6.3
CVE-2021-4294 LOW
OpenShift OSIN - Timing Discrepancy
CVSS 2.6
CVE-2021-42016 HIGH
Siemens RUGGEDCOM ROS - Observable Timing Discrepancy in Third-Party Component
CVSS 7.5
CVE-2021-43298 CRITICAL
GoAhead < 5.1.4 - Unauthenticated Password Brute-Force via Timing Attack
CVSS 9.8
CVE-2021-26318 MEDIUM
AMD Athlon, Athlon Pro, EPYC, Ryzen, and Ryzen Pro Firmware - Observable Timing Discrepancy via PREFETCH Instructions
CVSS 4.7
CVE-2021-26314 MEDIUM
Xen - Observable Timing Discrepancy via Floating Point Value Injection
CVSS 5.5
CVE-2021-26313 MEDIUM
Xen - Observable Timing Discrepancy via Speculative Code Store Bypass
CVSS 5.5
CVE-2021-31406 MEDIUM
Vaadin Flow 3.0.0-5.0.3 and Vaadin 15.0.0-18.0.6 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2021-31404 MEDIUM
Vaadin Flow 1.0.0-1.0.13 and Vaadin 10.0.0-10.0.16 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2021-31403 MEDIUM
Vaadin 7.0.0-7.7.23 and 8.0.0-8.12.2 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2020-35165 MEDIUM
Dell BSAFE <4.1.5-4.6 - Info Disclosure
CVSS 5.1
CVE-2020-1926 MEDIUM
Apache Hive <2.3.8 - Info Disclosure
CVSS 5.9
CVE-2020-15237 MEDIUM
Shrine < 3.3.0 - Observable Timing Discrepancy in Derivation Endpoint Signature Verification
CVSS 5.9
Details
Vulnerabilities 137