CVE-2025-0693
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/01/2025
Last modified:
15/04/2026
Description
Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM



