VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 13 of 31
  • CVE-2024-25051MedApr 2, 2025
    risk 0.43cvss 6.6epss 0.00

    IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.

  • CVE-2024-0008MedFeb 14, 2024
    risk 0.43cvss 6.6epss 0.01

    Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

  • CVE-2020-1666MedOct 16, 2020
    risk 0.43cvss 6.6epss 0.00

    The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access to the console the ability to resume a…

  • CVE-2018-2451MedAug 14, 2018
    risk 0.43cvss 6.6epss 0.01

    XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even…

  • CVE-2013-0335HigMar 22, 2013
    risk 0.43cvss 7.6epss 0.02

    OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

  • CVE-2026-9705MedJun 25, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls,…

  • CVE-2026-44648HigMay 29, 2026
    risk 0.42cvss 7.5epss 0.00

    SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authentication, storing all session…

  • CVE-2026-24894HigFeb 12, 2026
    risk 0.42cvss 7.5epss 0.00

    FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the…

  • CVE-2025-4677MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

  • CVE-2025-12278MedOct 26, 2025
    risk 0.42cvss 6.5epss 0.00

    Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-36040MedJul 31, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

  • CVE-2024-46040MedOct 7, 2024
    risk 0.42cvss 6.5epss 0.00

    IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during the Access Point Pairing mode leads the attacker to replay the Wi-Fi packets and forcefully turn off the…

  • CVE-2024-36523MedJun 12, 2024
    risk 0.42cvss 6.5epss 0.00

    An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator accounts. This is provided that the users do not log out of their deleted accounts.

  • CVE-2023-6787MedApr 25, 2024
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the…

  • CVE-2023-37919MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Cal.com account that is logged in on two or more devices, the account stays logged in on the other…

  • CVE-2022-40230MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.00

    "IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."

  • CVE-2022-41291MedOct 7, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.

  • CVE-2022-30699MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.01

    NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to…

  • CVE-2022-30698MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.01

    NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation…

  • CVE-2022-2306HigJul 5, 2022
    risk 0.42cvss 7.5epss 0.01

    Old session tokens can be used to authenticate to the application and send authenticated requests.