VYPR

CWE-204

Observable Response Discrepancy

BaseIncomplete

Description

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-331 · CAPEC-332 · CAPEC-541 · CAPEC-580

CVEs mapped to this weakness (179)

page 3 of 9
  • CVE-2024-0391MedMay 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-force and social engineering attacks.…

  • CVE-2026-20195MedMay 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is called.…

  • CVE-2025-3716MedMar 30, 2026
    risk 0.34cvss epss 0.00

    User enumeration in ESET Protect (on-prem) via Response Timing.

  • CVE-2025-13460MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.

  • CVE-2026-26744MedFeb 19, 2026
    risk 0.34cvss 5.3epss 0.00

    A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an unauthenticated attacker to determine…

  • CVE-2019-25338MedFeb 12, 2026
    risk 0.34cvss 5.3epss 0.00

    DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing…

  • CVE-2026-24664MedFeb 3, 2026
    risk 0.34cvss 5.3epss 0.00

    The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a username enumeration vulnerability allows unauthenticated attackers to identify valid user accounts by analyzing differences in the login response behavior.…

  • CVE-2025-62181MedDec 10, 2025
    risk 0.34cvss 5.3epss 0.00

    Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only…

  • CVE-2025-40806MedDec 9, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a…

  • CVE-2025-65899MedDec 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid users with incorrect passwords (invalid_password). This observable response…

  • CVE-2025-12994MedDec 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.

  • CVE-2025-59116MedNov 18, 2025
    risk 0.34cvss 5.3epss 0.00

    Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. Only version 4.1 was tested and confirmed as…

  • CVE-2025-25236MedNov 12, 2025
    risk 0.34cvss 5.3epss 0.00

    Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.

  • CVE-2025-62236MedOct 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.

  • CVE-2025-58586MedOct 6, 2025
    risk 0.34cvss 5.3epss 0.00

    For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

  • CVE-2025-56764MedSep 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.

  • CVE-2025-54834MedJul 31, 2025
    risk 0.34cvss 5.3epss 0.00

    OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.

  • CVE-2025-52899MedJul 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tuleap Enterprise Edition prior to 16.8-4 and 16.9-2, the forgot password form allows for user…

  • CVE-2025-27451MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

  • CVE-2025-49187MedJun 12, 2025
    risk 0.34cvss 5.3epss 0.00

    For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.