CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 13 of 17
- CVE-2019-14356MEDIUMCVSS 5.3EG 5.32019-10-31
On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. F…
- CVE-2019-6651MEDIUMCVSS 5.3EG 5.32019-09-25
In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow …
- CVE-2019-16669MEDIUMCVSS 5.3EG 5.32019-09-21
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.
- CVE-2019-16394MEDIUMCVSS 5.3EG 5.32019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
- CVE-2019-11465MEDIUMCVSS 5.3EG 5.32019-09-10
An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the use…
- CVE-2019-13599MEDIUMCVSS 5.3EG 5.32019-08-21
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.
- CVE-2019-15132MEDIUMCVSS 5.3EG 5.32019-08-17
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions fo…
- CVE-2019-12743MEDIUMCVSS 5.3EG 5.32019-07-29
HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response…
- CVE-2019-13383MEDIUMCVSS 5.3EG 5.32019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.
- CVE-2019-10848MEDIUMCVSS 5.3EG 5.32019-05-24
Computrols CBAS 18.0.0 allows Username Enumeration.
- CVE-2018-14597MEDIUMCVSS 5.3EG 5.32018-10-17
CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.
- CVE-2018-10949MEDIUMCVSS 5.3EG 5.32018-05-10
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.
- CVE-2018-0134MEDIUMCVSS 5.3EG 5.32018-02-08
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS s…
- CVE-2017-5107MEDIUMCVSS 5.3EG 5.32017-10-27
A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.
- CVE-2017-7006MEDIUMCVSS 5.3EG 5.32017-07-20
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing s…
- CVE-2017-8055MEDIUMCVSS 5.3EG 5.32017-04-22
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and in…
- CVE-2016-9129MEDIUMCVSS 5.3EG 5.32017-03-28
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the m…
- CVE-2021-36201MEDIUMCVSS 4.3EG 5.32022-10-11
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
- CVE-2026-73409MEDIUMCVSS 5.1EG 5.12026-07-24
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could subm…
- CVE-2024-7881MEDIUMCVSS 5.1EG 5.12025-01-28
An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.
- CVE-2024-10929MEDIUMCVSS 5.1EG 5.12025-01-22
In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.
- CVE-2020-35165MEDIUMCVSS 5.1EG 5.12024-05-22
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2023-25000MEDIUMCVSS 5.0EG 5.02023-03-30
HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host …
- CVE-2005-1650MEDIUMCVSS v2 5.0EG 5.02005-05-18
The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
- CVE-2005-0918MEDIUMCVSS v2 5.0EG 5.02005-05-05
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Jav…
- CVE-2004-1428MEDIUMCVSS v2 5.0EG 5.02004-12-31
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
- CVE-2004-2150MEDIUMCVSS v2 5.0EG 5.02004-12-31
Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.
- CVE-2004-2252MEDIUMCVSS v2 5.0EG 5.02004-12-31
The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.
- CVE-2004-0243MEDIUMCVSS v2 5.0EG 5.02004-11-23
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
- CVE-2004-0294MEDIUMCVSS v2 5.0EG 5.02004-11-23
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
- CVE-2004-0778MEDIUMCVSS v2 5.0EG 5.02004-10-20
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be return…
- CVE-2004-1602MEDIUMCVSS v2 5.0EG 5.02004-10-15
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
- CVE-2003-0637MEDIUMCVSS v2 5.0EG 5.02003-08-27
Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.
- CVE-2003-0190MEDIUMCVSS v2 5.0EG 5.02003-05-12
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
- CVE-2003-0078MEDIUMCVSS v2 5.0EG 5.02003-03-03
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to…
- CVE-2002-2094MEDIUMCVSS v2 5.0EG 5.02002-12-31
Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error message if the parent is incorrect, but …
- CVE-2002-0514MEDIUMCVSS v2 5.0EG 5.02002-08-12
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.
- CVE-2002-0515MEDIUMCVSS v2 5.0EG 5.02002-08-12
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.
- CVE-2002-0208MEDIUMCVSS v2 5.0EG 5.02002-05-16
PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire.
- CVE-2001-1483MEDIUMCVSS v2 5.0EG 5.02001-12-31
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account doe…
- CVE-2001-1528MEDIUMCVSS v2 5.0EG 5.02001-12-31
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
- CVE-2000-1117MEDIUMCVSS v2 5.0EG 5.02001-01-09
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemR…
- CVE-2021-24117MEDIUMCVSS 4.9EG 4.92021-07-14
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on s…
- CVE-2021-24119MEDIUMCVSS 4.9EG 4.92021-07-14
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on sof…
- CVE-2021-24116MEDIUMCVSS 4.9EG 4.92021-07-14
In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software runni…
- CVE-2023-3897MEDIUMCVSS 4.8EG 4.82023-07-25
Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. This issue affects SureMDM On-premise: 6.31 and below v…
- CVE-2023-32694MEDIUMCVSS 4.8EG 4.82023-05-25
Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order …
- CVE-2026-3580MEDIUMCVSS 4.7EG 4.72026-03-19
In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by GCC when targeting RISC-V RV32I with -O3. This transformation breaks the side-channel resistance of ECC scalar multipl…
- CVE-2025-8774MEDIUMCVSS 4.7EG 4.72025-08-09
A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component L1 Data Cache Handler. The manipulation leads to observable timin…
- CVE-2023-20583MEDIUMCVSS 4.7EG 4.72023-08-01
A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →