← Back
CWE-204

168 CVEs • Abstraction: Base

Observable Response Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

JSON object

Loading...

CVEs (168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Piccolo Orm
1Piccolo
Jun 17, 2026
Sep 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such that they would be able to successfully...Show more
Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such that they would be able to successfully generate a list of valid users on the platform. As Piccolo on its own does not also enforce strong passwords, these lists of valid accounts are likely to be used in a password spray attack with the outcome being attempted takeover of user accounts on the platform. The impact of this vulnerability is minor as it requires chaining with other attack vectors in order to gain more then simply a list of valid users on the underlying platform. The likelihood of this vulnerability is possible as it requires minimal skills to pull off, especially given the underlying login functionality for Piccolo based sites is open source. This issue has been patched in version 0.121.0.Show less
1Password Recovery Project
1Password Recovery
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the datab...Show more
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.Show less
1Silverwaregames
1Silverwaregames
Jun 17, 2026
Aug 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only...Show more
Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter the code" form if the email is associated with a member of the site. Since version 1.3.6, the "Enter the code" form is always returned, showing the message "If the entered email is associated with an account, a code will be sent now". This change prevents potential violators from determining if our site has a user with the specified email.Show less
1Sulu
1Sulu
Jun 17, 2026
Aug 4, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not usi...Show more
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue. The vulnerability has been patched in version 2.5.10. Show less
1Tadirantele
1Aeonix
Jun 17, 2026
Jul 30, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
1Sick
1Icr890 4 Firmware
Jun 17, 2026
Jul 10, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.
1Moxa
1Tn 5900 Firmware
Jun 17, 2026
Jul 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web l...Show more
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users. Show less
1Avaya
1Ix Workforce Engagement
Jun 17, 2026
May 30, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
1Snapone
1Orvc
Jun 17, 2026
May 22, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their inf...Show more
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information. Show less
1Teltonika
1Remote Management System
Jun 17, 2026
May 22, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already bee...Show more
Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MAC address of a device has already been claimed, or whether the attempt to claim a device was successful. An attacker could exploit this to create a list of the serial numbers and MAC addresses of all devices cloud-connected to the Remote Management System. Show less
1Sick
7Ftmg Esd15axx Firmware
Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 more
Jun 17, 2026
May 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing...Show more
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.Show less
1Mendix
1Forgot Password
Jun 17, 2026
Apr 11, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatib...Show more
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.1.1). The affected versions of the module contain an observable response discrepancy issue that could allow an attacker to retrieve sensitive information.Show less
1Answer
1Answer
Jun 17, 2026
Mar 21, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
1Vantage6
1Vantage6
Jun 17, 2026
Mar 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt...Show more
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots from obtaining usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily. This issue has been fixed in version 3.8.0. Show less
1Linuxfoundation
1Harbor
Jun 17, 2026
Dec 26, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
1Ghost
1Ghost
Jun 17, 2026
Dec 22, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTT...Show more
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.Show less
1Getkirby
1Kirby
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the c...Show more
Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only be exploited for targeted attacks because the attack does not scale to brute force. The problem has been patched in Kirby 3.5.8.2, Kirby 3.6.6.2, Kirby 3.7.5.1, and Kirby 3.8.1. In all of the mentioned releases, the maintainers have rewritten the affected code so that the delay is also inserted after the brute force limit is reached.Show less
1Johnsoncontrols
1C Cure 9000 Firmware
Jun 17, 2026
Oct 11, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
2Helmholz
Mbconnectline
4Mbconnect24
Mymbconnect24Myrex24+1 more
Jun 17, 2026
Sep 14, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v...Show more
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.Show less
1Codesys
1Visualization
Jun 17, 2026
Aug 23, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.