Falhas do tipo CWE-203

350 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2023-5410HIGHA potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP isEPSS 0.2%CVE-2025-13736LOWUsername Enumeration via Login Interface in Multiple WSO2 Products Allows User Account DiscoveryEPSS 0.2%CVE-2025-8774LOWriscv-boom SonicBOOM L1 Data Cache timing discrepancyEPSS 0.2%CVE-2025-65185LOWThere is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by enteriEPSS 0.2%CVE-2024-47153MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-8993MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-8994MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-47154MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-47155MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-8992MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.2%CVE-2024-47150LOWSome Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.EPSS 0.1%CVE-2024-47156LOWInformation Leak Vulnerability in Honor ProductEPSS 0.1%CVE-2024-47149LOWSome Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptiEPSS 0.1%CVE-2025-13912LOWPotential non-constant time compiled code with Clang LLVMEPSS 0.1%CVE-2026-28490HIGHAuthlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding OracleEPSS 0.1%CVE-2026-4040MEDIUMOpenClaw File Existence tools.exec.safeBins information exposureEPSS 0.1%CVE-2026-3580LOWCompiler-induced timing leak in sp_256_get_entry_256_9 on RISC-VEPSS 0.1%CVE-2025-48561MEDIUMIn multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This couldEPSS 0.1%CVE-2022-20538MEDIUMIn getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due toEPSS 0.1%CVE-2022-20535LOWIn registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without queEPSS 0.1%