CWE-204
186 CVEs • Abstraction: Base
Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
CVEs (186)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sonicwall 6Sma 100 Firmware Sma 200 FirmwareSma 210 Firmware+3 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37...Show more |
1Mbconnectline 2Mbconnect24 Mymbconnect24Jun 17, 2026 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts. |
1Inhandnetworks 1Ir615 Firmware Jun 17, 2026 Oct 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate different user accounts. |
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a worka...Show more |
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on emai...Show more |
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them. |