CVE-2025-0693

Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
Configurations

No configuration.

History

No history.

Information

Published : 2025-01-23 22:15

Updated : 2025-10-14 19:15


NVD link : CVE-2025-0693

Mitre link : CVE-2025-0693

CVE.ORG link : CVE-2025-0693


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy

CWE-208

Observable Timing Discrepancy