Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jan 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account. | |
Title | Issue with AWS Sign-in IAM User Login Flow - Possible Username Enumeration | |
Weaknesses | CWE-204 CWE-208 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2025-01-24T19:45:25.302Z
Reserved: 2025-01-23T20:36:22.905Z
Link: CVE-2025-0693

No data.

Status : Received
Published: 2025-01-23T22:15:15.397
Modified: 2025-01-23T22:15:15.397
Link: CVE-2025-0693

No data.