VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 18 of 40
  • CVE-2022-44381MedDec 25, 2022
    risk 0.35cvss 5.3epss 0.01

    Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.

  • CVE-2022-46392MedDec 15, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim…

  • CVE-2022-20940MedNov 15, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack…

  • CVE-2022-40084MedOct 20, 2022
    risk 0.35cvss 5.3epss 0.01

    OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

  • CVE-2022-37146MedSep 8, 2022
    risk 0.35cvss 5.3epss 0.01

    The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their…

  • CVE-2022-1989MedAug 23, 2022
    risk 0.35cvss 5.3epss 0.01

    All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.

  • CVE-2022-20752MedJul 6, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is…

  • CVE-2021-41634MedJun 24, 2022
    risk 0.35cvss 5.3epss 0.01

    A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.

  • CVE-2022-24043MedMay 20, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application fails…

  • CVE-2021-33845MedMay 6, 2022
    risk 0.35cvss 5.3epss 0.01

    The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.

  • CVE-2022-0564MedFeb 21, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare…

  • CVE-2022-24032MedJan 30, 2022
    risk 0.35cvss 5.3epss 0.01

    Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a different error message when the username is valid.

  • CVE-2019-25056MedJan 26, 2022
    risk 0.35cvss 5.3epss 0.01

    In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.

  • CVE-2021-20147MedJan 3, 2022
    risk 0.35cvss 5.3epss 0.07

    ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

  • CVE-2020-35398MedDec 23, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.

  • CVE-2021-44876MedDec 21, 2021
    risk 0.35cvss 5.3epss 0.01

    Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the…

  • CVE-2021-44875MedDec 21, 2021
    risk 0.35cvss 5.3epss 0.01

    Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the…

  • CVE-2021-44554MedDec 20, 2021
    risk 0.35cvss 5.3epss 0.01

    Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different…

  • CVE-2021-43398MedNov 4, 2021
    risk 0.35cvss 5.3epss 0.02

    Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct…

  • CVE-2021-37151MedSep 1, 2021
    risk 0.35cvss 5.3epss 0.01

    CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one…