CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 7 of 16
- CVE-2021-39788MEDIUMCVSS 5.5EG 5.52022-03-30
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional exec…
- CVE-2021-39791MEDIUMCVSS 5.5EG 5.52022-03-30
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executi…
- CVE-2021-41634MEDIUMCVSS 5.3EG 5.32022-06-24
A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
- CVE-2021-42016HIGHCVSS 7.5EG 7.52022-03-08
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M969, RUGGEDCOM M969F, RUGGEDCOM RMC30, RUGGEDCOM RMC838…
- CVE-2021-4286LOWCVSS 2.6EG 2.62022-12-27
A vulnerability, which was classified as problematic, has been found in cocagne pysrp up to 1.0.16. This issue affects the function calculate_x of the file srp/_ctsrp.py. The manipulation leads to information exposure through discrepancy. …
- CVE-2021-4294LOWCVSS 2.6EG 2.62022-12-28
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name o…
- CVE-2021-43398MEDIUMCVSS 5.3EG 5.32021-11-04
Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. Th…
- CVE-2021-43823MEDIUMCVSS 6.5EG 6.52021-12-13
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in private source code could be guessed by an authenticated but unauthorized actor. This issue aff…
- CVE-2021-44421MEDIUMCVSS 5.5EG 5.52022-03-10
The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via side-channel analysis.
- CVE-2021-44554MEDIUMCVSS 5.3EG 5.32021-12-20
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message retur…
- CVE-2021-44848MEDIUMCVSS 5.3EG 5.32021-12-13
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
- CVE-2021-44875MEDIUMCVSS 5.3EG 5.32021-12-21
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application coun…
- CVE-2021-44876MEDIUMCVSS 5.3EG 5.32021-12-21
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application coun…
- CVE-2021-45901MEDIUMCVSS 5.3EG 5.32022-02-10
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
- CVE-2021-45925MEDIUMCVSS 5.3EG 5.32022-10-24
Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
- CVE-2021-46744MEDIUMCVSS 6.5EG 6.52022-05-11
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
- CVE-2021-46778HIGHCVSS 5.6EG 7.52022-08-10
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention lev…
- CVE-2021-46876MEDIUMCVSS 5.3EG 5.32023-03-12
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.
- CVE-2021-47226HIGHCVSS 7.1EG 7.12024-05-21
In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Invalidate FPU state after a failed XRSTOR from a user buffer Both Intel and AMD consider it to be architecturally valid for XRSTOR to fail with #PF but nonethe…
- CVE-2021-47664MEDIUMCVSS 5.3EG 5.32025-04-24
Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.
- CVE-2022-0564MEDIUMCVSS 5.3EG 5.32022-02-21
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful explo…
- CVE-2022-0569MEDIUMCVSS 5.3EG 5.32022-02-14
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
- CVE-2022-0823MEDIUMCVSS 6.2EG 6.22022-06-09
An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.
- CVE-2022-1139MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1146MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1318MEDIUMCVSS 6.2EG 6.22022-04-20
Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would…
- CVE-2022-1989MEDIUMCVSS 5.3EG 5.32022-08-23
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.
- CVE-2022-20242MEDIUMCVSS 5.5EG 5.52022-08-11
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges …
- CVE-2022-20249LOWCVSS 3.3EG 3.32022-08-11
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2022-20251LOWCVSS 3.3EG 3.32022-08-11
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2022-20252LOWCVSS 3.3EG 3.32022-08-11
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privil…
- CVE-2022-20264MEDIUMCVSS 5.5EG 5.52023-10-30
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution pr…
- CVE-2022-20275MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20276MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20277MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20279MEDIUMCVSS 5.5EG 5.52022-08-12
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20291MEDIUMCVSS 5.5EG 5.52022-08-12
In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privile…
- CVE-2022-20293MEDIUMCVSS 5.5EG 5.52022-08-12
In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileg…
- CVE-2022-20304MEDIUMCVSS 5.5EG 5.52022-08-12
In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exp…
- CVE-2022-20307LOWCVSS 3.3EG 3.32022-08-12
In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution p…
- CVE-2022-20309LOWCVSS 3.3EG 3.32022-08-12
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2022-20316LOWCVSS 3.3EG 3.32022-08-12
In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2022-20318LOWCVSS 3.3EG 3.32022-08-12
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2022-20320LOWCVSS 3.3EG 3.32022-08-12
In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2022-20324MEDIUMCVSS 5.5EG 5.52022-08-12
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges …
- CVE-2022-20531MEDIUMCVSS 5.5EG 5.52022-12-16
In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2022-20535LOWCVSS 3.3EG 3.32022-12-16
In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information di…
- CVE-2022-20538MEDIUMCVSS 5.5EG 5.52022-12-16
In getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no addit…
- CVE-2022-20559LOWCVSS 3.3EG 3.32022-12-16
In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosu…
- CVE-2022-20752MEDIUMCVSS 5.3EG 5.32022-07-06
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →