CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 4 of 16
- CVE-2020-13413MEDIUMCVSS 5.3EG 5.32020-05-22
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
- CVE-2020-13844MEDIUMCVSS 5.5EG 5.52020-06-08
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-l…
- CVE-2020-13998MEDIUMCVSS 5.3EG 5.32020-06-11
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affe…
- CVE-2020-14002MEDIUMCVSS 5.9EG 5.92020-06-29
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cac…
- CVE-2020-14145MEDIUMCVSS 5.9EG 5.92020-06-29
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the …
- CVE-2020-1459HIGHCVSS 7.5EG 7.52020-08-17
An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with lo…
- CVE-2020-15151HIGHCVSS 8.0EG 8.02020-08-20
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-202…
- CVE-2020-15237MEDIUMCVSS 5.9EG 5.92020-10-05
In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a timing attack to guess the signature of the derivation URL. The problem has been fixed by comparing sent and calculated si…
- CVE-2020-15392MEDIUMCVSS 5.3EG 5.32020-07-07
A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a…
- CVE-2020-16150MEDIUMCVSS 5.5EG 5.52020-09-02
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference ba…
- CVE-2020-1685MEDIUMCVSS 5.8EG 5.82020-10-16
When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under certain conditions. Given a firewall fi…
- CVE-2020-17478HIGHCVSS 7.5EG 7.52020-08-10
ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.
- CVE-2020-1926MEDIUMCVSS 5.9EG 5.92021-03-16
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
- CVE-2020-1968LOWCVSS 3.7EG 3.72020-09-09
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result …
- CVE-2020-2101MEDIUMCVSS 5.3EG 5.32020-01-29
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
- CVE-2020-2102MEDIUMCVSS 5.3EG 5.32020-01-29
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
- CVE-2020-24008MEDIUMCVSS 5.3EG 5.32020-08-26
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- CVE-2020-24512LOWCVSS 3.3EG 3.32021-06-09
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2020-25065HIGHCVSS 7.5EG 7.52020-08-31
An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-170010 (August 2020).
- CVE-2020-25082LOWCVSS 3.8EG 3.82021-08-10
An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Disc…
- CVE-2020-25200MEDIUMCVSS 5.3EG 5.32020-10-01
Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server w…
- CVE-2020-25657MEDIUMCVSS 5.9EG 5.92021-01-12
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerabilit…
- CVE-2020-26062MEDIUMCVSS 5.3EG 5.32024-11-18
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication respo…
- CVE-2020-26939MEDIUMCVSS 5.3EG 5.32020-11-02
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.cry…
- CVE-2020-27026MEDIUMCVSS 5.5EG 5.52020-12-15
During boot, the device unlock interface behaves differently depending on if a fingerprint registered to the device is present. This could lead to local information disclosure with no additional execution privileges needed. User interactio…
- CVE-2020-27170MEDIUMCVSS 4.7EG 4.72021-03-20
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive inf…
- CVE-2020-27211MEDIUMCVSS 5.7EG 5.72021-05-21
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
- CVE-2020-28208MEDIUMCVSS 5.3EG 5.32021-01-08
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
- CVE-2020-28368MEDIUMCVSS 4.4EG 4.42020-11-10
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one …
- CVE-2020-29480LOWCVSS 2.3EG 2.32020-12-15
An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for ev…
- CVE-2020-3509HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the supervisor to crash, which could result in a denial of service (D…
- CVE-2020-35165MEDIUMCVSS 5.1EG 5.12024-05-22
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2020-35398MEDIUMCVSS 5.3EG 5.32021-12-23
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
- CVE-2020-35473MEDIUMCVSS 4.3EG 4.32022-11-08
An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2, may be used to iden…
- CVE-2020-35480MEDIUMCVSS 5.3EG 5.32020-12-18
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently,…
- CVE-2020-35518MEDIUMCVSS 5.3EG 5.32021-03-26
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
- CVE-2020-35624MEDIUMCVSS 5.3EG 5.32020-12-21
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
- CVE-2020-3585MEDIUMCVSS 5.3EG 5.32020-10-21
A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain acce…
- CVE-2020-36421MEDIUMCVSS 5.3EG 5.32021-07-19
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
- CVE-2020-36422MEDIUMCVSS 5.3EG 5.32021-07-19
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restar…
- CVE-2020-36424MEDIUMCVSS 4.7EG 4.72021-07-19
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
- CVE-2020-36517HIGHCVSS 7.5EG 7.52022-03-10
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
- CVE-2020-36888MEDIUMCVSS 5.3EG 5.32025-12-10
SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguis…
- CVE-2020-4028MEDIUMCVSS 5.3EG 5.32020-06-23
Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist o…
- CVE-2020-4660MEDIUMCVSS 5.3EG 5.32020-10-12
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186140.
- CVE-2020-4661MEDIUMCVSS 5.3EG 5.32020-10-12
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186142.
- CVE-2020-4699MEDIUMCVSS 5.3EG 5.32020-10-12
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947.
- CVE-2020-5143MEDIUMCVSS 5.3EG 5.32020-10-12
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 …
- CVE-2020-5929MEDIUMCVSS 5.9EG 5.92020-09-25
In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) D…
- CVE-2020-6400MEDIUMCVSS 6.5EG 6.52020-02-11
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →