SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33880

An attacker may be able to guess a password via a timing attack.

MEDIUM 5.9EPSS 2.27%

Does this matter?

Lower severity and a low EPSS score (2.27%). Track it; it rarely justifies an emergency change on its own.

Description

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
2.27% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
websockets project/websockets · oracle/communications cloud native core policy · oracle/communications cloud native core security edge protection proxy · oracle/communications cloud native core service communication proxy · oracle/communications cloud native core unified data repository
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.