CVE-2025-0693

Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
Configurations

No configuration.

History

23 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 22:15

Updated : 2025-01-23 22:15


NVD link : CVE-2025-0693

Mitre link : CVE-2025-0693

CVE.ORG link : CVE-2025-0693


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy

CWE-208

Observable Timing Discrepancy