CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
794 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 1 of 16
- CVE-2000-1117MEDIUMCVSS v2 5.0EG 5.02001-01-09
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemR…
- CVE-2001-1387LOWCVSS v2 2.1EG 2.12001-11-05
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an in…
- CVE-2001-1483MEDIUMCVSS v2 5.0EG 5.02001-12-31
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account doe…
- CVE-2001-1528MEDIUMCVSS v2 5.0EG 5.02001-12-31
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
- CVE-2002-0208MEDIUMCVSS v2 5.0EG 5.02002-05-16
PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire.
- CVE-2002-0514MEDIUMCVSS v2 5.0EG 5.02002-08-12
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.
- CVE-2002-0515MEDIUMCVSS v2 5.0EG 5.02002-08-12
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.
- CVE-2002-2094MEDIUMCVSS v2 5.0EG 5.02002-12-31
Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error message if the parent is incorrect, but …
- CVE-2003-0078MEDIUMCVSS v2 5.0EG 5.02003-03-03
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to…
- CVE-2003-0190MEDIUMCVSS v2 5.0EG 5.02003-05-12
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
- CVE-2003-0637MEDIUMCVSS v2 5.0EG 5.02003-08-27
Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.
- CVE-2004-0243MEDIUMCVSS v2 5.0EG 5.02004-11-23
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
- CVE-2004-0294MEDIUMCVSS v2 5.0EG 5.02004-11-23
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
- CVE-2004-0778MEDIUMCVSS v2 5.0EG 5.02004-10-20
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be return…
- CVE-2004-1428MEDIUMCVSS v2 5.0EG 5.02004-12-31
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
- CVE-2004-1602MEDIUMCVSS v2 5.0EG 5.02004-10-15
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
- CVE-2004-2150MEDIUMCVSS v2 5.0EG 5.02004-12-31
Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.
- CVE-2004-2252MEDIUMCVSS v2 5.0EG 5.02004-12-31
The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.
- CVE-2005-0918MEDIUMCVSS v2 5.0EG 5.02005-05-05
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Jav…
- CVE-2005-1650MEDIUMCVSS v2 5.0EG 5.02005-05-18
The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
- CVE-2010-10006LOWCVSS 2.6EG 2.62023-01-18
A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads to observable timing…
- CVE-2013-10006HIGHCVSS 2.6EG 7.52023-01-01
A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp. The manipulation of the argument strUserPass/strRPCUserCol…
- CVE-2013-1422MEDIUMCVSS 5.3EG 5.32020-02-04
webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
- CVE-2013-1620MEDIUMCVSS v2 4.3EG 4.32013-02-08
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to…
- CVE-2014-4156MEDIUMCVSS 5.3EG 5.32020-01-27
Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability
- CVE-2014-9720MEDIUMCVSS 6.5EG 6.52020-01-24
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted re…
- CVE-2015-0837MEDIUMCVSS 5.9EG 5.92019-11-29
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last…
- CVE-2015-8313MEDIUMCVSS 5.9EG 5.92019-12-20
GnuTLS incorrectly validates the first byte of padding in CBC modes
- CVE-2016-0762MEDIUMCVSS 5.9EG 5.92017-08-10
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a t…
- CVE-2016-15015LOWCVSS 2.6EG 2.62023-01-08
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepanc…
- CVE-2016-20012MEDIUMCVSS 5.3EG 5.32021-09-15
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when…
- CVE-2016-2178MEDIUMCVSS 5.5EG 5.52016-06-20
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel atta…
- CVE-2016-6489HIGHCVSS 7.5EG 7.52017-04-14
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
- CVE-2016-9129MEDIUMCVSS 5.3EG 5.32017-03-28
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the m…
- CVE-2017-1000385MEDIUMCVSS 5.9EG 5.92017-12-12
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Blei…
- CVE-2017-12373MEDIUMCVSS 5.9EG 5.92017-12-15
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbach…
- CVE-2017-13098HIGHCVSS 5.9EG 7.52017-12-13
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An att…
- CVE-2017-13099HIGHCVSS 5.9EG 7.52017-12-13
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is refe…
- CVE-2017-15533MEDIUMCVSS 5.9EG 5.92018-05-17
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the …
- CVE-2017-17427MEDIUMCVSS 5.9EG 5.92017-12-13
Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack"). This allows an attacker to decrypt observed traffic that has been encrypted with the…
- CVE-2017-18268MEDIUMCVSS 5.9EG 5.92018-05-17
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL co…
- CVE-2017-5107MEDIUMCVSS 5.3EG 5.32017-10-27
A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.
- CVE-2017-5715HIGHCVSS 5.6EG 8.32018-01-04
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
- CVE-2017-5753CRITICALCVSS 5.6EG 9.02018-01-04
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
- CVE-2017-6168HIGHCVSS 7.4EG 7.42017-11-17
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Adaptive Chosen Ciphe…
- CVE-2017-7006MEDIUMCVSS 5.3EG 5.32017-07-20
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing s…
- CVE-2017-8055MEDIUMCVSS 5.3EG 5.32017-04-22
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and in…
- CVE-2017-9735HIGHCVSS 7.5EG 7.52017-06-16
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
- CVE-2018-0134MEDIUMCVSS 5.3EG 5.32018-02-08
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS s…
- CVE-2018-0495MEDIUMCVSS 4.7EG 4.72018-06-13
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ec…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →