Falhas do tipo CWE-203

349 resultados

Discrepância Observável em Comportamento

Ocorre quando o sistema exibe comportamentos ou mensagens diferentes dependendo de informações secretas (senha, token, chave), permitindo que um atacante deduza essas informações através de análise de resposta. O perigo está em vazar conhecimento que deveria ser privado por meio de canais laterais, como tempo de resposta, mensagens de erro ou mudanças visuais.

Exemplo

Um formulário de login que retorna 'Usuário não existe' para usuários inválidos e 'Senha incorreta' para usuários válidos com senha errada. Um atacante usa essas mensagens diferentes para enumerar contas válidas sem nunca adivinhar a senha correta.

Como mitigar

Padronize respostas do sistema: retorne sempre a mesma mensagem genérica (ex: 'Credenciais inválidas') e o mesmo tempo de resposta, independentemente de qual parte falhou. Use técnicas como constant-time comparison para operações sensíveis e evite vazar informações através de timing, códigos HTTP diferenciados ou feedback textual discriminador.

CVE-2024-9513MEDIUMNetadmin Software NetAdmin IAM HTTP POST Request ReturnUserQuestionsFilled information exposureEPSS 1.7%CVE-2016-9129Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address EPSS 1.7%CVE-2024-39891MEDIUMIn the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access toEPSS 1.7%KEVCVE-2021-24651Poll Maker < 3.4.2 - Unauthenticated Time Based SQL InjectionEPSS 1.6%CVE-2024-0553HIGHGnutls: incomplete fix for cve-2023-5981EPSS 1.6%CVE-2020-5143SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based oEPSS 1.6%CVE-2020-36421MEDIUMAn issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secEPSS 1.6%CVE-2018-14597CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling EPSS 1.5%CVE-2018-16869MEDIUMA Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1EPSS 1.5%CVE-2023-0361HIGHA timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recEPSS 1.4%CVE-2024-5124HIGHTiming Attack Vulnerability in gaizhenbiao/chuanhuchatgptEPSS 1.4%CVE-2022-22120MEDIUMNocoDB - Observable Discrepancy in the password-reset featureEPSS 1.4%CVE-2022-36105MEDIUMUser Enumeration via Response Timing in TYPO3EPSS 1.3%CVE-2020-3585MEDIUMCisco Firepower 1000 Series Bleichenbacher Attack VulnerabilityEPSS 1.3%CVE-2021-1486MEDIUMCisco SD-WAN vManage HTTP Authentication User Enumeration VulnerabilityEPSS 1.2%CVE-2023-33850HIGHIBM GSKit-Crypto information disclosureEPSS 1.2%CVE-2021-29443MEDIUMPadding Oracle Attack due to Observable Timing Discrepancy in joseEPSS 1.2%CVE-2024-2408MEDIUMPHP is vulnerable to the Marvin AttackEPSS 1.2%CVE-2023-5992MEDIUMOpensc: side-channel leaks while stripping encryption pkcs#1 paddingEPSS 1.2%CVE-2023-50781HIGHM2crypto: bleichenbacher timing attacks in the rsa decryption api - incomplete fix for cve-2020-25657EPSS 1.1%