CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 12 of 17
- CVE-2021-44554MEDIUMCVSS 5.3EG 5.32021-12-20
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message retur…
- CVE-2021-44848MEDIUMCVSS 5.3EG 5.32021-12-13
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
- CVE-2021-43398MEDIUMCVSS 5.3EG 5.32021-11-04
Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. Th…
- CVE-2016-20012MEDIUMCVSS 5.3EG 5.32021-09-15
OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when…
- CVE-2021-39189MEDIUMCVSS 5.3EG 5.32021-09-15
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may appl…
- CVE-2021-37151MEDIUMCVSS 5.3EG 5.32021-09-01
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate be…
- CVE-2021-3642MEDIUMCVSS 5.3EG 5.32021-08-05
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confident…
- CVE-2021-37606MEDIUMCVSS 5.3EG 5.32021-07-30
Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that …
- CVE-2021-20113MEDIUMCVSS 5.3EG 5.32021-07-30
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If a…
- CVE-2020-36422MEDIUMCVSS 5.3EG 5.32021-07-19
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restar…
- CVE-2020-36421MEDIUMCVSS 5.3EG 5.32021-07-19
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
- CVE-2021-32528MEDIUMCVSS 5.3EG 5.32021-07-07
Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system information without permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
- CVE-2021-29621MEDIUMCVSS 5.3EG 5.32021-06-07
Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time fr…
- CVE-2021-29687MEDIUMCVSS 5.3EG 5.32021-05-20
IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018
- CVE-2021-21424MEDIUMCVSS 5.3EG 5.32021-05-13
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or n…
- CVE-2021-1486MEDIUMCVSS 5.3EG 5.32021-05-06
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability b…
- CVE-2021-31866MEDIUMCVSS 5.3EG 5.32021-04-28
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
- CVE-2020-35518MEDIUMCVSS 5.3EG 5.32021-03-26
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
- CVE-2021-27583MEDIUMCVSS 5.3EG 5.32021-02-23
In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVE-2020-28208MEDIUMCVSS 5.3EG 5.32021-01-08
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
- CVE-2019-12953MEDIUMCVSS 5.3EG 5.32020-12-30
Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.
- CVE-2020-35624MEDIUMCVSS 5.3EG 5.32020-12-21
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
- CVE-2020-35480MEDIUMCVSS 5.3EG 5.32020-12-18
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently,…
- CVE-2020-7962MEDIUMCVSS 5.3EG 5.32020-11-13
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for…
- CVE-2020-26939MEDIUMCVSS 5.3EG 5.32020-11-02
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.cry…
- CVE-2020-4699MEDIUMCVSS 5.3EG 5.32020-10-12
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947.
- CVE-2020-4661MEDIUMCVSS 5.3EG 5.32020-10-12
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186142.
- CVE-2020-4660MEDIUMCVSS 5.3EG 5.32020-10-12
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186140.
- CVE-2020-5143MEDIUMCVSS 5.3EG 5.32020-10-12
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 …
- CVE-2020-25200MEDIUMCVSS 5.3EG 5.32020-10-01
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server w…
- CVE-2020-24008MEDIUMCVSS 5.3EG 5.32020-08-26
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- CVE-2020-11625MEDIUMCVSS 5.3EG 5.32020-07-23
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. Failed web UI login attempts elicit different responses depending on whether a…
- CVE-2020-15392MEDIUMCVSS 5.3EG 5.32020-07-07
A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a…
- CVE-2020-11735MEDIUMCVSS 5.3EG 5.32020-06-25
The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."
- CVE-2020-4028MEDIUMCVSS 5.3EG 5.32020-06-23
Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist o…
- CVE-2020-13998MEDIUMCVSS 5.3EG 5.32020-06-11
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affe…
- CVE-2020-13413MEDIUMCVSS 5.3EG 5.32020-05-22
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
- CVE-2020-11576MEDIUMCVSS 5.3EG 5.32020-04-08
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing username and 404 ot…
- CVE-2019-5135MEDIUMCVSS 5.3EG 5.32020-03-11
An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which ca…
- CVE-2020-10102MEDIUMCVSS 5.3EG 5.32020-03-05
An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to guess valid user emails. In the current implementation, the application responds differentl…
- CVE-2020-7959MEDIUMCVSS 5.3EG 5.32020-02-17
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a…
- CVE-2020-8989MEDIUMCVSS 5.3EG 5.32020-02-13
In the Voatz application 2020-01-01 for Android, the amount of data transmitted during a single voter's vote depends on the different lengths of the metadata across the available voting choices, which makes it easier for remote attackers t…
- CVE-2013-1422MEDIUMCVSS 5.3EG 5.32020-02-04
webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
- CVE-2020-2102MEDIUMCVSS 5.3EG 5.32020-01-29
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
- CVE-2020-2101MEDIUMCVSS 5.3EG 5.32020-01-29
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
- CVE-2014-4156MEDIUMCVSS 5.3EG 5.32020-01-27
Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability
- CVE-2019-16516MEDIUMCVSS 5.3EG 5.32020-01-23
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given …
- CVE-2019-19805MEDIUMCVSS 5.3EG 5.32019-12-30
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an attacker to e…
- CVE-2019-13684MEDIUMCVSS 5.3EG 5.32019-11-25
Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2019-18886MEDIUMCVSS 5.3EG 5.32019-11-21
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users fu…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →