CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
724 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 10 of 15
- CVE-2023-21350MEDIUMCVSS 5.5EG 5.52023-10-30
In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2023-21354MEDIUMCVSS 5.5EG 5.52023-10-30
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executi…
- CVE-2023-22359MEDIUMCVSS 4.3EG 4.32023-06-26
User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
- CVE-2023-23449MEDIUMCVSS 5.3EG 5.32023-05-15
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses…
- CVE-2023-23584MEDIUMCVSS 4.3EG 4.32023-12-18
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 p…
- CVE-2023-24598MEDIUMCVSS 4.3EG 4.32023-05-29
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.
- CVE-2023-25000MEDIUMCVSS 5.0EG 5.02023-03-30
HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host …
- CVE-2023-25529HIGHCVSS 8.0EG 8.02023-09-20
NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A succes…
- CVE-2023-25728MEDIUMCVSS 6.5EG 6.52023-06-02
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.…
- CVE-2023-25741MEDIUMCVSS 6.5EG 6.52023-06-02
When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until fur…
- CVE-2023-25806MEDIUMCVSS 5.3EG 5.32023-03-02
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it…
- CVE-2023-26071HIGHCVSS 7.5EG 7.52023-03-28
An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that rev…
- CVE-2023-26215HIGHCVSS 7.7EG 7.72023-05-25
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application access to read system files that are accessible to the web server. Affected releases are TIBC…
- CVE-2023-26556CRITICALCVSS 9.1EG 9.12023-04-21
io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is not constant time (there is an if statement in a loop). One…
- CVE-2023-26557HIGHCVSS 7.5EG 7.52023-04-21
io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modular exponentiation, or modular inverse. An example leak is …
- CVE-2023-26560MEDIUMCVSS 6.5EG 6.52023-04-26
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
- CVE-2023-27283MEDIUMCVSS 5.3EG 5.32024-05-04
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
- CVE-2023-27464MEDIUMCVSS 5.3EG 5.32023-04-11
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions <…
- CVE-2023-27870MEDIUMCVSS 5.9EG 5.92023-05-11
IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in progress. IBM X-Force ID: 249518.
- CVE-2023-27931MEDIUMCVSS 5.5EG 5.52023-05-08
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.3, tvOS 16.4, watchOS 9.4. An app may be able to access user-sensitive…
- CVE-2023-28015MEDIUMCVSS 5.3EG 5.32023-05-23
The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker c…
- CVE-2023-28200MEDIUMCVSS 5.5EG 5.52023-05-08
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory.
- CVE-2023-28412MEDIUMCVSS 5.3EG 5.32023-05-22
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information. …
- CVE-2023-28770HIGHCVSS 7.5EG 7.52023-04-27
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and…
- CVE-2023-28840HIGHCVSS 7.5EG 7.52023-04-04
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as mob…
- CVE-2023-29850HIGHCVSS 7.5EG 7.52023-04-14
SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
- CVE-2023-30308MEDIUMCVSS 6.5EG 6.52024-05-28
An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions which could lead to a denial of service.
- CVE-2023-30312HIGHCVSS 7.3EG 7.32024-05-28
An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of service, impersonating the client to the server (e.g., for access to files over FTP), a…
- CVE-2023-30458MEDIUMCVSS 5.3EG 5.32023-04-24
A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username…
- CVE-2023-31186MEDIUMCVSS 5.3EG 5.32023-05-30
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
- CVE-2023-3139MEDIUMCVSS 6.1EG 6.12023-07-04
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
- CVE-2023-3221MEDIUMCVSS 5.3EG 5.32023-09-04
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.
- CVE-2023-32342HIGHCVSS 7.5EG 7.52023-05-30
IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could expl…
- CVE-2023-32691MEDIUMCVSS 5.9EG 5.92023-05-30
gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compar…
- CVE-2023-32694MEDIUMCVSS 4.8EG 4.82023-05-25
Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order …
- CVE-2023-3336MEDIUMCVSS 5.3EG 5.32023-07-05
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enabl…
- CVE-2023-33518MEDIUMCVSS 5.3EG 5.32023-06-05
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.
- CVE-2023-33741HIGHCVSS 7.5EG 7.52023-05-30
Macrovideo v380pro v1.4.97 shares the device id and password when sharing the device.
- CVE-2023-33850HIGHCVSS 7.5EG 7.52023-08-22
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker cou…
- CVE-2023-34344MEDIUMCVSS 5.3EG 5.32023-06-12
AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure.
- CVE-2023-3462MEDIUMCVSS 5.3EG 5.32023-07-31
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account …
- CVE-2023-34669HIGHCVSS 7.5EG 7.52023-07-17
TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
- CVE-2023-34878HIGHCVSS 7.5EG 7.52023-06-14
An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/download-zip.
- CVE-2023-3529MEDIUMCVSS 5.3EG 5.32023-07-06
A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unknown part of the file /LandingPages/api/otp/send?id=[ID][ampersand]method=sms of the component OTP URI Interface. The m…
- CVE-2023-35698MEDIUMCVSS 5.3EG 5.32023-07-10
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.
- CVE-2023-3604HIGHCVSS 7.5EG 7.52023-08-21
The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.
- CVE-2023-36127HIGHCVSS 7.5EG 7.52023-10-10
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attac…
- CVE-2023-36325LOWCVSS 3.7EG 3.72024-10-09
i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior…
- CVE-2023-3640HIGHCVSS 7.0EG 7.02023-07-24
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-05…
- CVE-2023-37217MEDIUMCVSS 5.3EG 5.32023-07-30
Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →