CWE-613
Insufficient Session Expiration
Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (608)
page 1 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-2595 | Cri | 0.68 | 9.8 | 0.17 | Feb 12, 2020 | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string. | ||
| CVE-2020-27422 | Cri | 0.67 | 9.8 | 0.08 | Nov 16, 2020 | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account. | ||
| CVE-2024-8888 | Cri | 0.65 | 10.0 | 0.00 | Sep 18, 2024 | An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods… | ||
| CVE-2025-59786 | Cri | 0.64 | 9.8 | 0.00 | Mar 4, 2026 | 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application. | ||
| CVE-2026-26342 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared… | ||
| CVE-2026-1435 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2026 | Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued… | ||
| CVE-2024-13996 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This… | ||
| CVE-2025-53826 | Cri | 0.64 | 9.8 | 0.01 | Jul 15, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs… | ||
| CVE-2024-13280 | Cri | 0.64 | 9.8 | 0.00 | Jan 9, 2025 | Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2. | ||
| CVE-2024-43685 | Cri | 0.64 | 9.8 | 0.00 | Oct 4, 2024 | Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | ||
| CVE-2024-29401 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2024 | xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything. | ||
| CVE-2023-35857 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | In Siren Investigate before 13.2.2, session keys remain active even after logging out. | ||
| CVE-2022-36179 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Fusiondirectory 1.3 suffers from Improper Session Handling. | ||
| CVE-2022-22318 | Cri | 0.64 | 9.8 | 0.00 | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | ||
| CVE-2022-22317 | Cri | 0.64 | 9.8 | 0.00 | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. | ||
| CVE-2021-22820 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products:… | ||
| CVE-2020-27416 | Cri | 0.64 | 9.8 | 0.02 | Dec 8, 2021 | Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account. | ||
| CVE-2021-40849 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2021 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges. | ||
| CVE-2021-38823 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2021 | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser. | ||
| CVE-2021-37333 | Cri | 0.64 | 9.8 | 0.01 | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser. |
- risk 0.68cvss 9.8epss 0.17
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
- risk 0.67cvss 9.8epss 0.08
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
- risk 0.65cvss 10.0epss 0.00
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods…
- risk 0.64cvss 9.8epss 0.00
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
- risk 0.64cvss 9.8epss 0.01
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared…
- risk 0.64cvss 9.8epss 0.00
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued…
- risk 0.64cvss 9.8epss 0.01
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This…
- risk 0.64cvss 9.8epss 0.01
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs…
- risk 0.64cvss 9.8epss 0.00
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.
- risk 0.64cvss 9.8epss 0.00
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
- risk 0.64cvss 9.8epss 0.01
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
- risk 0.64cvss 9.8epss 0.01
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
- risk 0.64cvss 9.8epss 0.01
Fusiondirectory 1.3 suffers from Improper Session Handling.
- risk 0.64cvss 9.8epss 0.00
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- risk 0.64cvss 9.8epss 0.00
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
- risk 0.64cvss 9.8epss 0.01
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products:…
- risk 0.64cvss 9.8epss 0.02
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.
- risk 0.64cvss 9.8epss 0.01
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.
- risk 0.64cvss 9.8epss 0.02
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.
- risk 0.64cvss 9.8epss 0.01
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.