Security Advisory

CVE-2025-0693

5.3
MEDIUM

Vulnerability Description

Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.
Published Date January 23, 2025
Official Source NIST NVD Advisory