BaseIncomplete
CWE-203Observable Discrepancy
Category: other
Description
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Common consequences· 2
- Confidentiality / Access Control — Read Application Data, Bypass Protection MechanismAn attacker can gain access to sensitive information about the system, including authentication information that may allow an attacker to gain access to the system. Other security-relevant information about the operation or internal state of the product may be revealed to an unauthorized actor, such as whether a particular operation was successful or not.
- Confidentiality — Read Application DataIn some cases, discrepancies can be used by attackers to form a side channel. When cryptographic primitives are vulnerable to side-channel attacks, this could be used to reveal unencrypted plaintext in the worst case.
Potential mitigations· 2
- [Architecture and Design]
- [Implementation]
Related CAPEC attack patterns· 1
References
Exploits (incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Black Box Reverse Engineeringcapec-189 | 100% | live |
(incoming)5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-10890cve-2025-10890 | 0% | live |
| Vulnerability | CVE-2025-27667cve-2025-27667 | 0% | live |
| Vulnerability | CVE-2026-23519cve-2026-23519 | 0% | live |
| Vulnerability | CVE-2026-41588cve-2026-41588 | 0% | live |
| KEVEntry | Twilio Authy Information Disclosure Vulnerabilitykev-cve-2024-39891 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.