CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2021-26313 MEDIUM
Xen - Observable Timing Discrepancy via Speculative Code Store Bypass
CVSS 5.5
CVE-2021-33560 HIGH
Libgcrypt <1.8.8 & <1.9.3 - Info Disclosure
CVSS 7.5
CVE-2021-29621 MEDIUM
Flask-AppBuilder <= 3.2.3 - Unauthenticated User Enumeration via Timing Attack
CVSS 5.3
CVE-2021-33880 MEDIUM
websockets < 9.1 - Timing Attack via HTTP Basic Authentication
CVSS 5.9
CVE-2021-33838 HIGH
luca < 1.7.4 - Information Disclosure via Check-In State Request Timing
CVSS 7.5
CVE-2021-22892 HIGH
Rocket.Chat <v3.13 - Info Disclosure
CVSS 7.5
CVE-2021-29415 MEDIUM
nordicsemi nRF52840_firmware < 2021-03-29 - ECDSA Private Key Recovery via Non-Constant Time Implementation
CVSS 5.5
CVE-2021-29687 MEDIUM
IBM Security Identity Manager 7.0.2 - Username Enumeration via Login Response Discrepancy
CVSS 5.3
CVE-2021-27342 MEDIUM
D-Link Router DIR-842 v3.0.2 - Auth Bypass
CVSS 5.9
CVE-2021-21424 MEDIUM
Symfony 3.4.0-3.4.48 - Unauthorized User Enumeration via Switch User Functionality
CVSS 5.3
CVE-2021-1486 MEDIUM
Cisco SD-WAN vManage <20.3.3 & Catalyst SD-WAN Manager 20.4-20.4.1 - Unauthenticated User Enumeration
CVSS 5.3
CVE-2021-31866 MEDIUM
Redmine < 4.0.9 and 4.1.x < 4.1.3 - Timing Attack via String Comparison in SysController and MailHandlerController
CVSS 5.3
CVE-2021-31406 MEDIUM
Vaadin Flow 3.0.0-5.0.3 and Vaadin 15.0.0-18.0.6 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2021-31404 MEDIUM
Vaadin Flow 1.0.0-1.0.13 and Vaadin 10.0.0-10.0.16 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2021-31403 MEDIUM
Vaadin 7.0.0-7.7.23 and 8.0.0-8.12.2 - Observable Timing Discrepancy in CSRF Token Comparison
CVSS 4.0
CVE-2021-29446 MEDIUM
jose-node-cjs-runtime < 3.11.4 - Timing Side-Channel in AES_CBC_HMAC_SHA2 Decryption
CVSS 5.9
CVE-2021-29445 MEDIUM
jose-node-esm-runtime < 3.11.4 - Timing Side-Channel in AES_CBC_HMAC_SHA2 Decryption
CVSS 5.9
CVE-2021-29444 MEDIUM
jose-node-cjs-runtime < 3.11.4 - Timing Side-Channel in AES_CBC_HMAC_SHA2 Decryption
CVSS 5.9
CVE-2021-29443 MEDIUM
jose 1.0.0-1.28.0 - Padding Oracle via AES_CBC_HMAC_SHA2 Decryption
CVSS 5.9
CVE-2021-21181 MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-21173 MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-27583 MEDIUM
Directus 8.0.0-8.8.1 - User Enumeration via Password Reset Feature
CVSS 5.3
CVE-2021-0321 MEDIUM
Android 11 - Local Information Disclosure via Package Installation Side Channel
CVSS 5.5
CVE-2020-36888 MEDIUM
SpinetiX Fusion Digital Signage 3.4.8 - Info Disclosure
CVSS 5.3
CVE-2020-26062 MEDIUM
Cisco Unified Computing System - Unauthenticated Username Enumeration via Authentication Response Discrepancy
CVSS 5.3
Details
Vulnerabilities 751