VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 17 of 39
  • CVE-2023-46739MedJan 3, 2024
    risk 0.35cvss 6.5epss 0.00

    CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could allow an untrusted attacker to steal user passwords by carrying out a timing attack. The root case of the…

  • CVE-2023-47102MedNov 7, 2023
    risk 0.35cvss 5.3epss 0.01

    UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.

  • CVE-2023-5722MedOct 25, 2023
    risk 0.35cvss 5.3epss 0.01

    Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a server-supplied Vary header. This vulnerability affects Firefox < 119.

  • CVE-2023-44216MedSep 27, 2023
    risk 0.35cvss 5.3epss 0.02

    PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can…

  • CVE-2023-23449MedMay 15, 2023
    risk 0.35cvss 5.3epss 0.01

    Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.

  • CVE-2023-30458MedApr 24, 2023
    risk 0.35cvss 5.3epss 0.01

    A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending…

  • CVE-2022-30332MedJan 10, 2023
    risk 0.35cvss 5.3epss 0.01

    In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via…

  • CVE-2022-41765MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.

  • CVE-2022-44381MedDec 25, 2022
    risk 0.35cvss 5.3epss 0.01

    Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.

  • CVE-2022-46392MedDec 15, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim…

  • CVE-2022-20940MedNov 15, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack…

  • CVE-2022-40084MedOct 20, 2022
    risk 0.35cvss 5.3epss 0.01

    OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

  • CVE-2022-37146MedSep 8, 2022
    risk 0.35cvss 5.3epss 0.01

    The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their…

  • CVE-2022-1989MedAug 23, 2022
    risk 0.35cvss 5.3epss 0.01

    All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.

  • CVE-2022-20752MedJul 6, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is…

  • CVE-2021-41634MedJun 24, 2022
    risk 0.35cvss 5.3epss 0.01

    A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.

  • CVE-2022-24043MedMay 20, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application fails…

  • CVE-2021-33845MedMay 6, 2022
    risk 0.35cvss 5.3epss 0.01

    The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.

  • CVE-2022-0564MedFeb 21, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare…

  • CVE-2022-24032MedJan 30, 2022
    risk 0.35cvss 5.3epss 0.01

    Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a different error message when the username is valid.