VYPR

CWE-324

Use of a Key Past its Expiration Date

BaseDraftLikelihood: Low

Description

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

While the expiration of keys does not necessarily ensure that they are compromised, it is a significant concern that keys which remain in use for prolonged periods of time have a decreasing probability of integrity. For this reason, it is important to replace keys within a period of time proportional to their strength.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (26)

page 1 of 2
  • CVE-2024-36031CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem for DNS resolution as…

  • CVE-2019-10643CriApr 17, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao 4.7 allows Use of a Key Past its Expiration Date.

  • CVE-2022-35401HigJan 10, 2023
    risk 0.54cvss 8.1epss 0.21

    An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to…

  • CVE-2025-2291HigApr 16, 2025
    risk 0.53cvss 8.1epss 0.00

    Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

  • CVE-2021-33020HigApr 1, 2022
    risk 0.53cvss 8.2epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

  • CVE-2026-43585HigMay 6, 2026
    risk 0.46cvss 8.1epss 0.01

    OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer…

  • CVE-2022-2447MedSep 1, 2022
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than…

  • CVE-2025-33012MedNov 7, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

  • CVE-2025-48813MedOct 14, 2025
    risk 0.41cvss 6.3epss 0.00

    Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

  • CVE-2019-3790MedJun 6, 2019
    risk 0.40cvss 6.1epss 0.01

    The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser…

  • CVE-2026-52809MedJun 24, 2026
    risk 0.37cvss 6.8epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.Auth.ResetPasswordCodeLives. The token lifetime is baked into the token itself at generation time…

  • CVE-2025-13723MedMar 13, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token

  • CVE-2022-24732MedMar 9, 2022
    risk 0.34cvss 6.3epss 0.00

    Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired…

  • CVE-2024-7318MedSep 9, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1…

  • CVE-2024-6299MedJun 25, 2024
    risk 0.31cvss 4.8epss 0.00

    Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

  • CVE-2024-38277MedJun 18, 2024
    risk 0.28cvss 5.4epss 0.00

    A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

  • CVE-2024-31895MedMay 22, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176.

  • CVE-2024-31894MedMay 22, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288175.

  • CVE-2024-31893MedMay 22, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: 288174.

  • CVE-2023-5342MedAug 14, 2025
    risk 0.27cvss 4.1epss 0.00

    The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.