CWE-203
Observable Discrepancy
Description
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-189
CVEs mapped to this weakness (762)
page 21 of 39| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24391 | Med | 0.34 | 5.3 | 0.00 | Jul 14, 2025 | A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS… | ||
| CVE-2023-38327 | Med | 0.34 | 5.3 | 0.00 | Jul 11, 2025 | An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web applications based on server response. | ||
| CVE-2025-27451 | Med | 0.34 | 5.3 | 0.00 | Jul 3, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | ||
| CVE-2024-47057 | Med | 0.34 | 5.3 | 0.00 | May 28, 2025 | SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration… | ||
| CVE-2025-3939 | Med | 0.34 | 5.3 | 0.00 | May 22, 2025 | Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara… | ||
| CVE-2021-47664 | — | Med | 0.34 | 5.3 | 0.00 | Apr 24, 2025 | Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames. | |
| CVE-2025-30344 | Med | 0.34 | 5.3 | 0.00 | Mar 21, 2025 | An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100… | ||
| CVE-2023-37482 | — | Med | 0.34 | 5.3 | 0.01 | Feb 11, 2025 | The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames. | |
| CVE-2025-24506 | Med | 0.34 | — | 0.00 | Jan 30, 2025 | A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types. | ||
| CVE-2023-37413 | Med | 0.34 | 5.3 | 0.00 | Jan 29, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy. | ||
| CVE-2024-35114 | Med | 0.34 | 5.3 | 0.00 | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts. | ||
| CVE-2024-56738 | Med | 0.34 | 5.3 | 0.00 | Dec 29, 2024 | GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks. | ||
| CVE-2024-54454 | Med | 0.34 | 5.3 | 0.00 | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a… | ||
| CVE-2024-11297 | Med | 0.34 | 5.3 | 0.01 | Dec 20, 2024 | The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract… | ||
| CVE-2024-41741 | Med | 0.34 | 5.3 | 0.00 | Nov 1, 2024 | IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system. | ||
| CVE-2024-49358 | Med | 0.34 | 5.3 | 0.00 | Oct 24, 2024 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http:///v1/users/login` in ZimaOS returns distinct responses based on whether a username exists or the password is… | ||
| CVE-2024-9398 | Med | 0.34 | 5.3 | 0.01 | Oct 1, 2024 | By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and… | ||
| CVE-2024-8651 | Med | 0.34 | 5.3 | 0.00 | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch… | ||
| CVE-2024-23984 | Med | 0.34 | 5.3 | 0.00 | Sep 16, 2024 | Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | ||
| CVE-2024-34336 | Med | 0.34 | 5.3 | 0.00 | Sep 12, 2024 | User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality. |
- risk 0.34cvss 5.3epss 0.00
A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web applications based on server response.
- risk 0.34cvss 5.3epss 0.00
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
- risk 0.34cvss 5.3epss 0.00
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration…
- risk 0.34cvss 5.3epss 0.00
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara…
- risk 0.34cvss 5.3epss 0.00
Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100…
- risk 0.34cvss 5.3epss 0.01
The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.
- risk 0.34cvss —epss 0.00
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
- risk 0.34cvss 5.3epss 0.00
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
- risk 0.34cvss 5.3epss 0.00
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.
- risk 0.34cvss 5.3epss 0.00
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a…
- risk 0.34cvss 5.3epss 0.01
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract…
- risk 0.34cvss 5.3epss 0.00
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system.
- risk 0.34cvss 5.3epss 0.00
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http:///v1/users/login` in ZimaOS returns distinct responses based on whether a username exists or the password is…
- risk 0.34cvss 5.3epss 0.01
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and…
- risk 0.34cvss 5.3epss 0.00
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch…
- risk 0.34cvss 5.3epss 0.00
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
- risk 0.34cvss 5.3epss 0.00
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.