VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 21 of 39
  • CVE-2025-24391MedJul 14, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS…

  • CVE-2023-38327MedJul 11, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web applications based on server response.

  • CVE-2025-27451MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

  • CVE-2024-47057MedMay 28, 2025
    risk 0.34cvss 5.3epss 0.00

    SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration…

  • CVE-2025-3939MedMay 22, 2025
    risk 0.34cvss 5.3epss 0.00

    Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara…

  • CVE-2021-47664MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.

  • CVE-2025-30344MedMar 21, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100…

  • CVE-2023-37482MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.01

    The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.

  • CVE-2025-24506MedJan 30, 2025
    risk 0.34cvss epss 0.00

    A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.

  • CVE-2023-37413MedJan 29, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

  • CVE-2024-35114MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.

  • CVE-2024-56738MedDec 29, 2024
    risk 0.34cvss 5.3epss 0.00

    GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

  • CVE-2024-54454MedDec 27, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a…

  • CVE-2024-11297MedDec 20, 2024
    risk 0.34cvss 5.3epss 0.01

    The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract…

  • CVE-2024-41741MedNov 1, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system.

  • CVE-2024-49358MedOct 24, 2024
    risk 0.34cvss 5.3epss 0.00

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http:///v1/users/login` in ZimaOS returns distinct responses based on whether a username exists or the password is…

  • CVE-2024-9398MedOct 1, 2024
    risk 0.34cvss 5.3epss 0.01

    By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and…

  • CVE-2024-8651MedSep 19, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch…

  • CVE-2024-23984MedSep 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2024-34336MedSep 12, 2024
    risk 0.34cvss 5.3epss 0.00

    User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.