CWE-385
45 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Covert Timing Channel
Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.
CVEs (45)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. |
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts. |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2M2crypto Project Redhat3Enterprise Linux M2cryptoUpdate InfrastructureJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 17, 2026 Jan 31, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext....Show more |
2Opencryptoki Project Redhat2Enterprise Linux OpencryptokiJun 17, 2026 Jan 31, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signin...Show more |
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECD...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGnutlsJun 17, 2026 Jan 16, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote...Show more |
RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An att...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJul 21, 2026 Jul 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the p...Show more |
2Dell Oracle6Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteDatabase+3 moreJun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. |
2Dell Oracle6Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteDatabase+3 moreJun 17, 2026 Jul 11, 2022 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. |
2Dell Oracle6Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteDatabase+3 moreJun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability. |
Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected system. Only customers with active BSAFE maintenance contracts can recei...Show more |
3Fedoraproject M2crypto ProjectRedhat4Enterprise Linux FedoraM2crypto+1 moreJun 17, 2026 Jan 12, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat fro...Show more |
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and o...Show more |
2Cryptography.io Oracle2Communications Cloud Native Core Network Function Cloud Native Environment CryptographyJun 17, 2026 Jan 11, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext. |
3Fedoraproject Python Rsa ProjectRedhat3Fedora Openstack PlatformPython RsaJun 17, 2026 Nov 12, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Jul 13, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. Wh...Show more |
2Dell Emc3Bsafe Crypto C Micro Edition Bsafe Micro Edition SuiteRsa Bsafe Crypto CJun 17, 2026 Sep 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) versions prior to 4.1.6.1 (in 4.1.x) and v...Show more |