CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

733 vulnerabilities with CWE-203
CVE-2022-20752 MEDIUM
Cisco Unified Communications Manager 12.5(1) - Observable Timing Discrepancy
CVSS 5.3
CVE-2022-34174 HIGH
Jenkins <2.355-<2.332.3 - Info Disclosure
CVSS 7.5
CVE-2022-24436 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 6.5
CVE-2022-23823 MEDIUM
AMD Athlon X4/Ryzen Threadripper PRO Firmware Info Disclosure via Timing Attack
CVSS 6.5
CVE-2022-27221 MEDIUM
SINEMA Remote Connect Server < 3.1 - Plaintext Secret Exposure via BREACH Attack
CVSS 5.9
CVE-2022-0823 MEDIUM
Zyxel GS1200 Series Firmware < 2.00 - Timing Side-Channel Password Guessing
CVSS 6.2
CVE-2022-32273 MEDIUM
OPSWAT MetaDefender Core < 5.1.2 - Authenticated Filename Enumeration via Observable Discrepancy
CVSS 4.3
CVE-2022-29185 MEDIUM
totp-rs < 1.1.0 - Observable Timing Discrepancy in Token Comparison
CVSS 4.2
CVE-2022-24043 MEDIUM
Siemens Desigo DXR2, PXC3, PXC4, PXC5 - Username Enumeration via Login Timing Side Channel
CVSS 5.3
CVE-2022-1318 MEDIUM
Hills ComNav < 3002-19 - Inadequate Encryption Strength in Local Network Configuration Traffic
CVSS 6.2
CVE-2022-27814 LOW
swhkd 1.1.5 - Arbitrary File Existence Test via -c Option
CVSS 3.3
CVE-2022-22356 MEDIUM
IBM MQ Appliance <9.2 - Info Disclosure
CVSS 6.5
CVE-2022-24784 LOW
Statamic < 3.2.39 - Exposure of Sensitive Information via REST API Users Endpoint
CVSS 3.7
CVE-2022-0564 MEDIUM
Qlik Sense Enterprise on Windows - Info Disclosure
CVSS 5.3
CVE-2022-23643 MEDIUM
Sourcegraph 3.35.0-3.35.1 - Authenticated Exposure of Sensitive Information via Code Monitoring Feature
CVSS 6.5
CVE-2022-0569 MEDIUM
Packagist snipe/snipe-it <5.3.9 - Info Disclosure
CVSS 5.3
CVE-2022-21659 MEDIUM
Flask-AppBuilder < 3.4.4 - Unauthenticated User Enumeration via Login Timing Discrepancy
CVSS 5.3
CVE-2022-24032 MEDIUM
Azenza AxiomSL ControllerView <10.8.1 - Info Disclosure
CVSS 5.3
CVE-2022-23304 CRITICAL
hostapd and wpa_supplicant < 2.10 - Side-Channel Attack via EAP-pwd Cache Access Patterns
CVSS 9.8
CVE-2022-23303 CRITICAL
hostapd and wpa_supplicant < 2.10 - Side Channel Attack via SAE Cache Access Patterns
CVSS 9.8
CVE-2022-23106 MEDIUM
Jenkins Configuration as Code Plugin < 1.55 - Authentication Token Timing Attack
CVSS 5.3
CVE-2022-22120 MEDIUM
NocoDB 0.9-0.83.8 - User Enumeration via Password Reset Error Message
CVSS 5.3
CVE-2021-47664 MEDIUM
Franka Emika Robot <=4.0.3 - Username Enumeration
CVSS 5.3
CVE-2021-47226 HIGH
Linux Kernel - Information Disclosure via FPU State Leak on XRSTOR Failure
CVSS 7.1
CVE-2021-20556 MEDIUM
IBM Cognos Controller <11.0.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 733