CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 7 of 17
- CVE-2020-10367MEDIUMCVSS 5.5EG 5.52024-11-10
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack.
- CVE-2024-50102MEDIUMCVSS 5.5EG 5.52024-11-05
In the Linux kernel, the following vulnerability has been resolved: x86: fix user address masking non-canonical speculation issue It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical accesses in kernel space. And so …
- CVE-2024-47678MEDIUMCVSS 5.5EG 5.52024-10-21
In the Linux kernel, the following vulnerability has been resolved: icmp: change the order of rate limits ICMP messages are ratelimited : After the blamed commits, the two rate limiters are applied in this order: 1) host wide ratelimit…
- CVE-2022-48730MEDIUMCVSS 5.5EG 5.52024-06-20
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the conten…
- CVE-2024-32926MEDIUMCVSS 5.5EG 5.52024-06-13
there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-23170MEDIUMCVSS 5.5EG 5.52024-01-31
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the att…
- CVE-2023-21354MEDIUMCVSS 5.5EG 5.52023-10-30
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executi…
- CVE-2023-21350MEDIUMCVSS 5.5EG 5.52023-10-30
In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2023-21344MEDIUMCVSS 5.5EG 5.52023-10-30
In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2023-21338MEDIUMCVSS 5.5EG 5.52023-10-30
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privile…
- CVE-2023-21336MEDIUMCVSS 5.5EG 5.52023-10-30
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileg…
- CVE-2023-21335MEDIUMCVSS 5.5EG 5.52023-10-30
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges n…
- CVE-2023-21333MEDIUMCVSS 5.5EG 5.52023-10-30
In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2023-21332MEDIUMCVSS 5.5EG 5.52023-10-30
In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2023-21331MEDIUMCVSS 5.5EG 5.52023-10-30
In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privilege…
- CVE-2023-21330MEDIUMCVSS 5.5EG 5.52023-10-30
In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21327MEDIUMCVSS 5.5EG 5.52023-10-30
In Permission Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution pr…
- CVE-2023-21326MEDIUMCVSS 5.5EG 5.52023-10-30
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executi…
- CVE-2023-21325MEDIUMCVSS 5.5EG 5.52023-10-30
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges n…
- CVE-2023-21323MEDIUMCVSS 5.5EG 5.52023-10-30
In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2023-21320MEDIUMCVSS 5.5EG 5.52023-10-30
In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges n…
- CVE-2023-21319MEDIUMCVSS 5.5EG 5.52023-10-30
In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is …
- CVE-2023-21318MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2023-21317MEDIUMCVSS 5.5EG 5.52023-10-30
In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privil…
- CVE-2023-21316MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2023-21306MEDIUMCVSS 5.5EG 5.52023-10-30
In ContentService, there is a possible way to read installed sync content providers due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interactio…
- CVE-2023-21305MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2023-21304MEDIUMCVSS 5.5EG 5.52023-10-30
In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21303MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee…
- CVE-2023-21302MEDIUMCVSS 5.5EG 5.52023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21301MEDIUMCVSS 5.5EG 5.52023-10-30
In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional executi…
- CVE-2023-21300MEDIUMCVSS 5.5EG 5.52023-10-30
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privil…
- CVE-2023-21299MEDIUMCVSS 5.5EG 5.52023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21296MEDIUMCVSS 5.5EG 5.52023-10-30
In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privilege…
- CVE-2023-21293MEDIUMCVSS 5.5EG 5.52023-10-30
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution…
- CVE-2022-20264MEDIUMCVSS 5.5EG 5.52023-10-30
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution pr…
- CVE-2022-42792MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive location information
- CVE-2023-28200MEDIUMCVSS 5.5EG 5.52023-05-08
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory.
- CVE-2023-27931MEDIUMCVSS 5.5EG 5.52023-05-08
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.3, tvOS 16.4, watchOS 9.4. An app may be able to access user-sensitive…
- CVE-2022-4543MEDIUMCVSS 5.5EG 5.52023-01-11
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.
- CVE-2022-20538MEDIUMCVSS 5.5EG 5.52022-12-16
In getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no addit…
- CVE-2022-20531MEDIUMCVSS 5.5EG 5.52022-12-16
In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2022-20324MEDIUMCVSS 5.5EG 5.52022-08-12
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges …
- CVE-2022-20304MEDIUMCVSS 5.5EG 5.52022-08-12
In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exp…
- CVE-2022-20293MEDIUMCVSS 5.5EG 5.52022-08-12
In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileg…
- CVE-2022-20291MEDIUMCVSS 5.5EG 5.52022-08-12
In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2022-20279MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20277MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20276MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20275MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →