CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 5 of 16
- CVE-2020-6473MEDIUMCVSS 6.5EG 6.52020-05-21
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2020-6531MEDIUMCVSS 4.3EG 4.32020-07-22
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2020-7959MEDIUMCVSS 5.3EG 5.32020-02-17
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a…
- CVE-2020-7962MEDIUMCVSS 5.3EG 5.32020-11-13
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for…
- CVE-2020-8695MEDIUMCVSS 5.5EG 5.52020-11-12
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2020-8989MEDIUMCVSS 5.3EG 5.32020-02-13
In the Voatz application 2020-01-01 for Android, the amount of data transmitted during a single voter's vote depends on the different lengths of the metadata across the available voting choices, which makes it easier for remote attackers t…
- CVE-2020-9389LOWCVSS 3.7EG 3.72021-02-03
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid userna…
- CVE-2020-9588HIGHCVSS 7.2EG 7.22020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
- CVE-2020-9690MEDIUMCVSS 4.2EG 4.22020-07-29
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
- CVE-2021-0001MEDIUMCVSS 4.7EG 4.72021-06-09
Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
- CVE-2021-0086MEDIUMCVSS 6.5EG 6.52021-06-09
Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
- CVE-2021-0089MEDIUMCVSS 6.5EG 6.52021-06-09
Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
- CVE-2021-0321MEDIUMCVSS 5.5EG 5.52021-01-11
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosure with no additiona…
- CVE-2021-0524MEDIUMCVSS 5.5EG 5.52022-02-11
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional executio…
- CVE-2021-0975MEDIUMCVSS 5.5EG 5.52022-08-11
In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure of installed packages with no addition…
- CVE-2021-0987LOWCVSS 3.3EG 3.32021-12-15
In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosu…
- CVE-2021-0988LOWCVSS 3.3EG 3.32021-12-15
In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to …
- CVE-2021-0989LOWCVSS 3.3EG 3.32021-12-15
In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information di…
- CVE-2021-0990LOWCVSS 3.3EG 3.32021-12-15
In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…
- CVE-2021-0995LOWCVSS 3.3EG 3.32021-12-15
In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inform…
- CVE-2021-1005MEDIUMCVSS 5.5EG 5.52021-12-15
In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosu…
- CVE-2021-1009MEDIUMCVSS 5.5EG 5.52021-12-15
In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disc…
- CVE-2021-1012MEDIUMCVSS 5.5EG 5.52021-12-15
In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…
- CVE-2021-1013MEDIUMCVSS 5.5EG 5.52021-12-15
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. Th…
- CVE-2021-1014MEDIUMCVSS 5.5EG 5.52021-12-15
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information dis…
- CVE-2021-1015LOWCVSS 3.3EG 3.32021-12-15
In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with …
- CVE-2021-1018LOWCVSS 3.3EG 3.32021-12-15
In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no ad…
- CVE-2021-1026MEDIUMCVSS 5.5EG 5.52021-12-15
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additi…
- CVE-2021-1030MEDIUMCVSS 5.5EG 5.52021-12-15
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local info…
- CVE-2021-1031LOWCVSS 3.3EG 3.32021-12-15
In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inform…
- CVE-2021-1032LOWCVSS 3.3EG 3.32021-12-15
In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no…
- CVE-2021-1109HIGHCVSS 7.2EG 7.22021-08-11
NVIDIA camera firmware contains a multistep, timing-related vulnerability where an unauthorized modification by camera resources may result in loss of data integrity or denial of service across several streams.
- CVE-2021-1486MEDIUMCVSS 5.3EG 5.32021-05-06
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability b…
- CVE-2021-1924CRITICALCVSS 9.0EG 9.02021-11-12
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Sna…
- CVE-2021-20049HIGHCVSS 7.5EG 7.52021-12-23
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x…
- CVE-2021-20113MEDIUMCVSS 5.3EG 5.32021-07-30
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If a…
- CVE-2021-20147MEDIUMCVSS 5.3EG 5.32022-01-03
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
- CVE-2021-20376MEDIUMCVSS 4.3EG 4.32021-10-07
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
- CVE-2021-20556MEDIUMCVSS 5.3EG 5.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
- CVE-2021-21173MEDIUMCVSS 6.5EG 6.52021-03-09
Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21181MEDIUMCVSS 6.5EG 6.52021-03-09
Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2021-21424MEDIUMCVSS 5.3EG 5.32021-05-13
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or n…
- CVE-2021-21575MEDIUMCVSS 5.9EG 5.92024-02-02
Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
- CVE-2021-22892HIGHCVSS 7.5EG 7.52021-05-27
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
- CVE-2021-24116MEDIUMCVSS 4.9EG 4.92021-07-14
In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software runni…
- CVE-2021-24117MEDIUMCVSS 4.9EG 4.92021-07-14
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on s…
- CVE-2021-24119MEDIUMCVSS 4.9EG 4.92021-07-14
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on sof…
- CVE-2021-24651HIGHCVSS 7.5EG 7.52021-10-11
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate …
- CVE-2021-26313MEDIUMCVSS 5.5EG 5.52021-06-09
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data …
- CVE-2021-26314MEDIUMCVSS 5.5EG 5.52021-06-09
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →