CVEbaza.plSłownik CWECWE-208
Common Weakness Enumeration

CWE-208

Observable Timing Discrepancy

Kategoria: BaseCVE: 184
Opis

Dwie oddzielne operacje w produkcie wymagają różnych ilości czasu do wykonania w sposób obserwowany przez uczestnika, ujawniając informacje istotne dla bezpieczeństwa o stanie produktu, takie jak powodzenie lub niepowodzenie danej operacji. Takie rozbieżności czasowe mogą być wykorzystane do uzyskania wrażliwych informacji o systemie.

Description (EN)

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Podatności CVE z CWE-208 (184)
9.8
CVSS
CRITICAL
CVE-2023-41313

Metoda uwierzytelniania w Apache Doris przed wersją 2.0.0 była podatna na ataki czasowe (timing attacks), umożliwiające zdalne odgadnięcie danych uwierzytelniających. Podatność uzyskała ocenę CVSS 9.8 (CRITICAL) i może prowadzić do pełnego przejęcia kontroli nad systemem.

pub. 2024-03-12
9.8
CVSS
CRITICAL
CVE-2021-43298

Implementacja uwierzytelniania HTTP Basic w serwerze Embedthis GoAhead nie stosuje porównania stałoczasowego (constant-time memcmp) ani ograniczenia liczby prób logowania. Umożliwia to zdalnemu atakującemu odgadnięcie hasła bajt po bajcie poprzez analizę czasu odpowiedzi serwera.

pub. 2022-01-25
9.0
CVSS
CRITICAL
CVE-2026-41588

RELATE, webowy system zarządzania materiałami dydaktycznymi, zawiera podatność typu timing attack w module uwierzytelniania (course/auth.py). Luka umożliwia atakującemu zdalnemu odgadnięcie tajnego klucza logowania poprzez analizę czasu odpowiedzi serwera.

pub. 2026-05-08
8.9
CVSS
HIGH
CVE-2026-23519

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (portable version). This vulnerability is fixed in 0.4.4.

pub. 2026-01-15
8.7
CVSS
HIGH
CVE-2026-72700

The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler). Because the token-submission endpoint (taskReset) also lacks rate limiting, an attacker could in principle send repeated token guesses against a known username and use the timing differences to attempt to recover a valid token, though the vendor rates the practical exploitability as low and no end-to-end network exploit has been demonstrated.

pub. 2026-08-25
8.7
CVSS
HIGH
CVE-2024-47178

basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.

pub. 2024-09-30
8.6
CVSS
HIGH
CVE-2024-42512

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.

pub. 2025-02-10
8.5
CVSS
HIGH
CVE-2026-43606

Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.

pub. 2026-08-11
8.5
CVSS
HIGH
CVE-2025-53940

Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 and below, Quiet's API for backend/frontend communication was using an insecure, not constant-time comparison function for token verification. This allowed for a potential timing attack where an attacker would try different token values and observe tiny differences in the response time (wrong characters fail faster) to guess the whole token one character at a time. This is fixed in version 6.0.1.

pub. 2025-07-24
8.3
CVSS
HIGH
CVE-2026-16731

OMICRON StationScout przed wersją 3.05 zawiera podatność typu cryptographic timing side-channel w mechanizmie uwierzytelnienia backendu, która pozwala nieuwierzytelnionemu atakującemu na sfałszowanie prawidłowych danych uwierzytelniających i całkowite ominięcie mechanizmów kontroli dostępu. Podatność jest szczególnie groźna, ponieważ nie wymaga żadnych uprawnień ani interakcji użytkownika.

pub. 2026-08-06
8.2
CVSS
HIGH
CVE-2026-69247

Biblioteka Python cryptography w wersjach od 44.0.0 do 49.x ujawnia wynik operacji RSA PKCS#1 v1.5 podczas deszyfrowania wiadomości PKCS#7 w kilku rozróżnialnych sposobach, w tym poprzez dokładną długość odszyfrowanego klucza oraz timing. Umożliwia to atakującemu zbudowanie tzw. wyroczni Bleichenbachera i odzyskanie klucza szyfrowania treści.

pub. 2026-08-03
8.2
CVSS
HIGH
CVE-2024-14041

Biblioteka Bouncy Castle dla Java zawiera podatność klasy timing side-channel (CWE-208) w implementacji algorytmu ML-KEM (CRYSTALS-Kyber), umożliwiającą odtworzenie długoterminowego klucza prywatnego. Atakujący mierzący czas wykonania dużej liczby operacji dekapsulacji może statystycznie odtworzyć sekretny klucz.

pub. 2026-07-28
8.2
CVSS
HIGH
CVE-2026-15432

Biblioteka kryptograficzna Tink podczas weryfikacji kodu MAC przy użyciu obiektu ChunkedMacVerification stosuje porównanie tagów w czasie niezmiennym (non constant time), co otwiera możliwość ataku side-channel opartego na pomiarze czasu odpowiedzi. Błąd może umożliwić atakującemu stopniowe odgadnięcie poprawnego tagu metodą bajt po bajcie.

pub. 2026-07-21
8.2
CVSS
HIGH
CVE-2026-54736

W framework'u Phalcon przed wersją 5.14.1 funkcja deszyfrowania stosuje niebezpieczne porównanie tagów HMAC podatne na atak czasowy (timing attack). Atakujący może wykorzystać mierzalne różnice czasu odpowiedzi, aby odtworzyć poprawny tag HMAC bajt po bajcie i dołączyć go do spreparowanych danych, które zostaną zaakceptowane przez framework jako autentyczne.

pub. 2026-07-10
8.2
CVSS
HIGH
CVE-2026-32935

phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.

pub. 2026-03-20
8.2
CVSS
HIGH
CVE-2026-28464

OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements. Remote attackers with network access to the hooks endpoint can exploit timing side-channels across multiple requests to gradually determine the authentication token.

pub. 2026-03-05
8.2
CVSS
HIGH
CVE-2026-3337

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

pub. 2026-03-02
8.2
CVSS
HIGH
CVE-2024-31074

Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.

pub. 2024-11-13
8.1
CVSS
HIGH
CVE-2026-16315

OMICRON StationGuard w wersjach przed 4.10 zawiera podatność kryptograficzną typu timing side-channel w backendowym mechanizmie uwierzytelniania. Umożliwia ona nieuwierzytelnionemu atakującemu sfałszowanie prawidłowych poświadczeń uwierzytelniających i całkowite ominięcie kontroli dostępu.

pub. 2026-08-06
8.1
CVSS
HIGH
CVE-2026-47783

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

pub. 2026-05-20
Pokazano 20 z 184 podatności
Informacje
ID: CWE-208
Typ: Base
Podatności: 184
MITRE CWE ↗
← Słownik CWE