CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 8 of 16
- CVE-2022-20866HIGHCVSS 7.4EG 7.52022-08-10
A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private ke…
- CVE-2022-20940MEDIUMCVSS 5.3EG 5.32022-11-15
A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of counter…
- CVE-2022-21659MEDIUMCVSS 5.3EG 5.32022-01-31
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate exis…
- CVE-2022-22120MEDIUMCVSS 5.3EG 5.32022-01-10
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered…
- CVE-2022-22356MEDIUMCVSS 6.5EG 6.52022-04-05
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487.
- CVE-2022-23106MEDIUMCVSS 5.3EG 5.32022-01-12
Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.
- CVE-2022-23303CRITICALCVSS 9.8EG 9.82022-01-17
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
- CVE-2022-23304CRITICALCVSS 9.8EG 9.82022-01-17
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
- CVE-2022-23643MEDIUMCVSS 6.5EG 6.52022-02-15
Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity in the Code Monitoring feature where strings in private source code could be guessed by an …
- CVE-2022-23823MEDIUMCVSS 6.5EG 6.52022-06-15
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
- CVE-2022-24032MEDIUMCVSS 5.3EG 5.32022-01-30
Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a different error message when the username is valid.
- CVE-2022-24043MEDIUMCVSS 5.3EG 5.32022-05-20
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The logi…
- CVE-2022-24436MEDIUMCVSS 6.5EG 6.52022-06-15
Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via network access.
- CVE-2022-24695MEDIUMCVSS 4.3EG 4.32023-06-02
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract t…
- CVE-2022-24784LOWCVSS 3.7EG 3.72022-03-25
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. …
- CVE-2022-24912HIGHCVSS 7.5EG 7.52022-07-29
The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret.…
- CVE-2022-25332MEDIUMCVSS 4.4EG 4.42023-10-19
The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with non-secure supervisor privileges by managing cache contents an…
- CVE-2022-2612MEDIUMCVSS 6.5EG 6.52022-08-12
Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTM…
- CVE-2022-26382MEDIUMCVSS 4.3EG 4.32022-12-22
While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by t…
- CVE-2022-27221MEDIUMCVSS 5.9EG 5.92022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An attacker in machine-in-the-middle could obtain plaintext secret values by observing length differences during a series of guesses in which a stri…
- CVE-2022-27814LOWCVSS 3.3EG 3.32022-04-14
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.
- CVE-2022-2891MEDIUMCVSS 5.9EG 5.92022-10-10
The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.
- CVE-2022-29185MEDIUMCVSS 4.2EG 4.22022-05-20
totp-rs is a Rust library that permits the creation of 2FA authentification tokens per time-based one-time password (TOTP). Prior to version 1.1.0, token comparison was not constant time, and could theorically be used to guess value of an …
- CVE-2022-30332MEDIUMCVSS 5.3EG 5.32023-01-10
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows re…
- CVE-2022-31142HIGHCVSS 7.5EG 7.52022-07-14
@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqual. A malicious attacker could estimate the length of one va…
- CVE-2022-3143HIGHCVSS 7.4EG 7.42023-01-13
wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values…
- CVE-2022-31742MEDIUMCVSS 6.5EG 6.52022-12-22
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linkin…
- CVE-2022-32218MEDIUMCVSS 4.3EG 4.32022-09-23
An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to the actionLinkHandler method was found to allow Message ID Enumeration with Regex MongoDB queries.
- CVE-2022-32273MEDIUMCVSS 4.3EG 4.32022-06-08
As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.
- CVE-2022-32296LOWCVSS 3.3EG 3.32022-06-05
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.
- CVE-2022-32425MEDIUMCVSS 5.3EG 5.32022-07-14
The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.
- CVE-2022-34125MEDIUMCVSS 6.5EG 6.52023-04-16
front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.
- CVE-2022-34174HIGHCVSS 7.5EG 7.52022-06-23
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, w…
- CVE-2022-34477HIGHCVSS 7.5EG 7.52022-12-22
The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulner…
- CVE-2022-34704MEDIUMCVSS 4.7EG 5.52022-08-09
Windows Defender Credential Guard Information Disclosure Vulnerability
- CVE-2022-35888MEDIUMCVSS 6.5EG 6.52022-09-29
Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on…
- CVE-2022-36105MEDIUMCVSS 5.3EG 5.32022-09-13
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend and frontend) can be used to distinguish between existing a…
- CVE-2022-36885MEDIUMCVSS 5.3EG 5.32022-07-27
Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook sig…
- CVE-2022-37146MEDIUMCVSS 5.3EG 5.32022-09-08
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users conf…
- CVE-2022-37459HIGHCVSS 7.8EG 7.82022-08-17
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retble…
- CVE-2022-3907HIGHCVSS 7.5EG 7.52022-12-05
The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.
- CVE-2022-39228MEDIUMCVSS 5.3EG 5.32023-03-01
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots fr…
- CVE-2022-40084MEDIUMCVSS 5.3EG 5.32022-10-20
OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.
- CVE-2022-4025MEDIUMCVSS 4.3EG 4.32023-01-02
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
- CVE-2022-40482MEDIUMCVSS 5.3EG 5.32023-04-25
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials …
- CVE-2022-4087MEDIUMCVSS 2.6EG 4.32022-11-21
A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to informatio…
- CVE-2022-40895CRITICALCVSS 9.1EG 9.12022-10-06
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to i…
- CVE-2022-40982MEDIUMCVSS 6.5EG 6.52023-08-11
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-41354MEDIUMCVSS 4.3EG 4.32023-03-27
An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.
- CVE-2022-41765MEDIUMCVSS 5.3EG 5.32022-12-26
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →