VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 34 of 39
  • CVE-2025-54999LowAug 9, 2025
    risk 0.17cvss 3.7epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao's userpass auth method, user enumeration was possible due to timing difference between…

  • CVE-2024-28868LowMar 20, 2024
    risk 0.17cvss 3.7epss 0.00

    Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively…

  • CVE-2024-21671LowJan 30, 2024
    risk 0.17cvss 3.7epss 0.00

    The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks. …

  • CVE-2020-11063LowMay 13, 2020
    risk 0.17cvss 3.7epss 0.01

    In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts. This has…

  • CVE-2025-8774LowAug 9, 2025
    risk 0.16cvss 2.5epss 0.00

    A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component L1 Data Cache Handler. The manipulation leads to observable timing discrepancy. Local access is required…

  • CVE-2022-46724LowAug 14, 2023
    risk 0.16cvss 2.4epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 16.4. A person with physical access to an iOS device may be able to view the last image used in Magnifier from the lock screen.

  • CVE-2019-14359LowAug 12, 2019
    risk 0.16cvss 2.4epss 0.00

    On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB…

  • CVE-2019-14357LowAug 10, 2019
    risk 0.16cvss 2.4epss 0.00

    On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB…

  • CVE-2019-14355LowAug 10, 2019
    risk 0.16cvss 2.4epss 0.00

    On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB…

  • CVE-2019-14354LowAug 10, 2019
    risk 0.16cvss 2.4epss 0.00

    On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in…

  • CVE-2026-4040LowMar 12, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs to be performed locally. Upgrading to…

  • CVE-2024-58262LowJul 27, 2025
    risk 0.12cvss 2.9epss 0.00

    The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.

  • CVE-2025-46570LowMay 29, 2025
    risk 0.10cvss 2.6epss 0.00

    vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token).…

  • CVE-2010-10006LowJan 18, 2023
    risk 0.10cvss 2.6epss 0.01

    A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads to observable timing discrepancy. The complexity of an…

  • CVE-2016-15015LowJan 8, 2023
    risk 0.10cvss 2.6epss 0.01

    A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather…

  • CVE-2013-10006LowJan 1, 2023
    risk 0.10cvss 2.6epss 0.01

    A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp. The manipulation of the argument strUserPass/strRPCUserColonPass leads to observable timing…

  • CVE-2021-4294LowDec 28, 2022
    risk 0.10cvss 2.6epss 0.01

    A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is…

  • CVE-2021-4286LowDec 27, 2022
    risk 0.10cvss 2.6epss 0.01

    A vulnerability, which was classified as problematic, has been found in cocagne pysrp up to 1.0.16. This issue affects the function calculate_x of the file srp/_ctsrp.py. The manipulation leads to information exposure through discrepancy. Upgrading to version 1.0.17 is able to…

  • CVE-2003-0190May 12, 2003
    risk 0.09cvss epss 0.77

    OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

  • CVE-2004-1602Oct 15, 2004
    risk 0.05cvss epss 0.31

    ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.