CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 9 of 16
- CVE-2022-41914LOWCVSS 3.7EG 3.72022-11-16
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a comparator that did no…
- CVE-2022-42288MEDIUMCVSS 5.3EG 5.32023-01-13
NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.
- CVE-2022-42792MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive location information
- CVE-2022-4304MEDIUMCVSS 5.9EG 5.92023-02-08
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have t…
- CVE-2022-43411MEDIUMCVSS 5.3EG 5.32022-10-19
Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webh…
- CVE-2022-43412MEDIUMCVSS 5.3EG 5.32022-10-19
Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to ob…
- CVE-2022-44381MEDIUMCVSS 5.3EG 5.32022-12-25
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
- CVE-2022-4499HIGHCVSS 7.5EG 7.52023-01-11
TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a side-channel attack. By measuring the response time of the httpd process, an attacker coul…
- CVE-2022-45163MEDIUMCVSS 5.3EG 5.32022-11-18
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i…
- CVE-2022-45177HIGHCVSS 7.5EG 7.52024-02-21
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and…
- CVE-2022-45403MEDIUMCVSS 6.5EG 6.52022-12-22
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media …
- CVE-2022-45416MEDIUMCVSS 6.5EG 6.52022-12-22
Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects …
- CVE-2022-4543MEDIUMCVSS 5.5EG 5.52023-01-11
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.
- CVE-2022-46392MEDIUMCVSS 5.3EG 5.32022-12-15
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA p…
- CVE-2022-46724LOWCVSS 2.4EG 2.42023-08-14
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 16.4. A person with physical access to an iOS device may be able to view the last image used in Magnifier from the lock …
- CVE-2022-47952LOWCVSS 3.3EG 3.32023-01-01
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "d…
- CVE-2022-48220MEDIUMCVSS 6.4EG 6.42024-02-14
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these p…
- CVE-2022-4823MEDIUMCVSS 3.1EG 5.92022-12-28
A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipulation of the argument signature leads to observable timing di…
- CVE-2022-48251HIGHCVSS 7.5EG 7.52023-01-10
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not…
- CVE-2022-48730MEDIUMCVSS 5.5EG 5.52024-06-20
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1 gadget as it's supplied by a user and used as an array index. Prevent the conten…
- CVE-2022-50800HIGHCVSS 7.5EG 7.52025-12-30
H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different usernames to the login_submit.cgi endpoint and analyze response…
- CVE-2023-0361HIGHCVSS 7.4EG 7.52023-02-15
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To …
- CVE-2023-0440MEDIUMCVSS 5.3EG 5.32023-01-23
Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6.
- CVE-2023-1538MEDIUMCVSS 5.3EG 5.32023-03-21
Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2023-1540MEDIUMCVSS 5.3EG 5.32023-03-21
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2023-1696HIGHCVSS 7.5EG 7.52023-05-20
The multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.
- CVE-2023-1707HIGHCVSS 7.5EG 7.52023-06-13
Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.
- CVE-2023-1998MEDIUMCVSS 5.6EG 5.62023-04-21
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud prov…
- CVE-2023-20569HIGHCVSS 4.7EG 7.52023-08-08
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disc…
- CVE-2023-20575MEDIUMCVSS 6.5EG 6.52023-07-11
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of se…
- CVE-2023-20583MEDIUMCVSS 4.7EG 4.72023-08-01
A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.…
- CVE-2023-21293MEDIUMCVSS 5.5EG 5.52023-10-30
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution…
- CVE-2023-21296MEDIUMCVSS 5.5EG 5.52023-10-30
In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privilege…
- CVE-2023-21298HIGHCVSS 7.8EG 7.82023-10-30
In Slice, there is a possible disclosure of installed applications due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2023-21299MEDIUMCVSS 5.5EG 5.52023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21300MEDIUMCVSS 5.5EG 5.52023-10-30
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privil…
- CVE-2023-21301MEDIUMCVSS 5.5EG 5.52023-10-30
In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional executi…
- CVE-2023-21302MEDIUMCVSS 5.5EG 5.52023-10-30
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21303MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges nee…
- CVE-2023-21304MEDIUMCVSS 5.5EG 5.52023-10-30
In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privi…
- CVE-2023-21305MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2023-21306MEDIUMCVSS 5.5EG 5.52023-10-30
In ContentService, there is a possible way to read installed sync content providers due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interactio…
- CVE-2023-21316MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2023-21317MEDIUMCVSS 5.5EG 5.52023-10-30
In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privil…
- CVE-2023-21318MEDIUMCVSS 5.5EG 5.52023-10-30
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges ne…
- CVE-2023-21319MEDIUMCVSS 5.5EG 5.52023-10-30
In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is …
- CVE-2023-21320MEDIUMCVSS 5.5EG 5.52023-10-30
In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges n…
- CVE-2023-21323MEDIUMCVSS 5.5EG 5.52023-10-30
In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv…
- CVE-2023-21324HIGHCVSS 7.8EG 7.82023-10-30
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution pr…
- CVE-2023-21325MEDIUMCVSS 5.5EG 5.52023-10-30
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges n…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →