CWE-613
Insufficient Session Expiration
Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (640)
page 1 of 32| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-2595 | Cri | 0.68 | 9.8 | 0.17 | Feb 12, 2020 | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string. | ||
| CVE-2020-27422 | Cri | 0.67 | 9.8 | 0.08 | Nov 16, 2020 | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account. | ||
| CVE-2024-8888 | Cri | 0.65 | 10.0 | 0.00 | Sep 18, 2024 | An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods… | ||
| CVE-2026-84480 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2026 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's… | ||
| CVE-2026-14950 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2026 | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access… | |
| CVE-2025-59786 | Cri | 0.64 | 9.8 | 0.00 | Mar 4, 2026 | 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application. | ||
| CVE-2026-26342 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared… | ||
| CVE-2026-1435 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2026 | Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued… | ||
| CVE-2024-13996 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This… | ||
| CVE-2025-53826 | Cri | 0.64 | 9.8 | 0.01 | Jul 15, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs… | ||
| CVE-2024-13280 | Cri | 0.64 | 9.8 | 0.00 | Jan 9, 2025 | Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2. | ||
| CVE-2024-43685 | Cri | 0.64 | 9.8 | 0.00 | Oct 4, 2024 | Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | ||
| CVE-2024-29401 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2024 | xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything. | ||
| CVE-2023-35857 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2023 | In Siren Investigate before 13.2.2, session keys remain active even after logging out. | ||
| CVE-2022-36179 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Fusiondirectory 1.3 suffers from Improper Session Handling. | ||
| CVE-2022-22318 | Cri | 0.64 | 9.8 | 0.00 | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | ||
| CVE-2022-22317 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. | ||
| CVE-2021-25992 | Cri | 0.64 | 9.8 | 0.02 | Feb 10, 2022 | In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks. | ||
| CVE-2021-22820 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products:… | ||
| CVE-2021-25981 | Cri | 0.64 | 9.8 | 0.02 | Jan 3, 2022 | In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin… |
- risk 0.68cvss 9.8epss 0.17
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
- risk 0.67cvss 9.8epss 0.08
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
- risk 0.65cvss 10.0epss 0.00
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods…
- risk 0.64cvss 9.8epss 0.01
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's…
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access…
- risk 0.64cvss 9.8epss 0.00
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
- risk 0.64cvss 9.8epss 0.01
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared…
- risk 0.64cvss 9.8epss 0.00
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued…
- risk 0.64cvss 9.8epss 0.01
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This…
- risk 0.64cvss 9.8epss 0.01
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs…
- risk 0.64cvss 9.8epss 0.00
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.
- risk 0.64cvss 9.8epss 0.00
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
- risk 0.64cvss 9.8epss 0.01
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
- risk 0.64cvss 9.8epss 0.01
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
- risk 0.64cvss 9.8epss 0.01
Fusiondirectory 1.3 suffers from Improper Session Handling.
- risk 0.64cvss 9.8epss 0.00
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- risk 0.64cvss 9.8epss 0.01
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
- risk 0.64cvss 9.8epss 0.02
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.
- risk 0.64cvss 9.8epss 0.01
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products:…
- risk 0.64cvss 9.8epss 0.02
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin…