What is CWE-203?
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Analyzing data...
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Analyzing data...
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Discrepancies may be observable based on timing, control flow, communications (such as replies or requests), or general behavior.
| Impact | Scope | Explanation |
|---|---|---|
| Read Application Data, Bypass Protection Mechanism | Confidentiality, Access Control | An attacker can gain access to sensitive information about the system, including authentication information that may allow an attacker to gain access to the system. Other security-relevant information about the operation or internal state of the product may be revealed to an unauthorized actor, such as whether a particular operation was successful or not. |
| Read Application Data | Confidentiality | In some cases, discrepancies can be used by attackers to form a side channel. When cryptographic primitives are vulnerable to side-channel attacks, this could be used to reveal unencrypted plaintext in the worst case. |
Below are representative vulnerabilities related to this CWE, prioritized by severity.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScanen