VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 4 of 22
  • CVE-2022-30605HigAug 22, 2022
    risk 0.58cvss 8.8epss 0.04

    A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger…

  • CVE-2018-5385HigJul 24, 2018
    risk 0.58cvss 8.8epss 0.04

    Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is…

  • CVE-2026-41613HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-25101CriMar 27, 2026
    risk 0.57cvss 9.8epss 0.00

    Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in…

  • CVE-2026-22082HigJan 9, 2026
    risk 0.57cvss epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting…

  • CVE-2023-53776HigDec 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue unauthorized requests to the device management API by leveraging the session binding…

  • CVE-2025-56400HigNov 24, 2025
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own…

  • CVE-2025-10228HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affects Agentis: before 4.44.

  • CVE-2025-53895HigJul 15, 2025
    risk 0.57cvss 8.8epss 0.00

    ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if they know its ID, due to a…

  • CVE-2024-13967HigJun 4, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web Server of EIBPORT. This issue affects EIBPORT V3 KNX: through 3.9.8; EIBPORT V3 KNX GSM: through 3.9.8.

  • CVE-2024-45368HigSep 13, 2024
    risk 0.57cvss 8.8epss 0.00

    The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E PLC's protocol execution, namely its acceptance of multiple distinct packets as valid authentication…

  • CVE-2024-37829HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.

  • CVE-2024-24552HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.00

    A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other user into authorizing a session ID of their choosing.

  • CVE-2024-23679CriJan 19, 2024
    risk 0.57cvss 9.8epss 0.01

    Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.

  • CVE-2023-0897HigOct 26, 2023
    risk 0.57cvss 8.8epss 0.00

    Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.

  • CVE-2023-45687HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.01

    A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authorizating a session id of their choosing

  • CVE-2023-37946HigJul 12, 2023
    risk 0.57cvss 8.8epss 0.01

    Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.

  • CVE-2023-34656HigJun 29, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru 4.1 allows attackers to gain escalated privileges.

  • CVE-2023-24456CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.

  • CVE-2023-24427CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.