VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 10 of 31
  • CVE-2017-12191HigFeb 28, 2018
    risk 0.48cvss 7.4epss 0.01

    A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could…

  • CVE-2017-6145HigOct 20, 2017
    risk 0.48cvss 7.3epss 0.01

    iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly re-validate…

  • CVE-2026-54479HigJun 25, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to…

  • CVE-2026-32663HigMar 20, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the…

  • CVE-2026-27649HigMar 20, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where…

  • CVE-2026-27764HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the…

  • CVE-2026-20748HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the…

  • CVE-2026-24912HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the…

  • CVE-2026-27647HigFeb 27, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where …

  • CVE-2026-26290HigFeb 27, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where …

  • CVE-2026-27652HigFeb 27, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where …

  • CVE-2026-25778HigFeb 27, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where …

  • CVE-2026-25711HigFeb 27, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where …

  • CVE-2026-20895HigFeb 27, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where …

  • CVE-2025-55705HigJan 22, 2026
    risk 0.47cvss 7.3epss 0.00

    This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can result in unauthorized access, data inconsistency, or potential manipulation of charging sessions. The lack of proper session…

  • CVE-2025-22386HigJan 4, 2025
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be…

  • CVE-2024-22389HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.01

    When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2023-42768HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.01

    When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST…

  • CVE-2023-37570HigAug 8, 2023
    risk 0.47cvss 7.2epss 0.01

    This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.

  • CVE-2019-9269HigSep 27, 2019
    risk 0.47cvss 7.3epss 0.00

    In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…