VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 2 of 31
  • CVE-2020-35358CriMar 15, 2021
    risk 0.64cvss 9.8epss 0.02

    DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers…

  • CVE-2020-6649CriFeb 8, 2021
    risk 0.64cvss 9.8epss 0.02

    An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical…

  • CVE-2020-29667CriDec 10, 2020
    risk 0.64cvss 9.8epss 0.03

    In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.

  • CVE-2020-27739CriOct 28, 2020
    risk 0.64cvss 9.8epss 0.02

    A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

  • CVE-2020-8234CriAug 21, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.

  • CVE-2020-17474CriAug 14, 2020
    risk 0.64cvss 9.8epss 0.01

    A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.

  • CVE-2016-11014CriOct 16, 2019
    risk 0.64cvss 9.8epss 0.03

    NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

  • CVE-2018-6634CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access to an account.

  • CVE-2016-6545CriJul 13, 2018
    risk 0.64cvss 9.8epss 0.03

    Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the…

  • CVE-2016-5069CriApr 10, 2017
    risk 0.64cvss 9.8epss 0.01

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.

  • CVE-2026-8670CriMay 22, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before 25.3.1.

  • CVE-2024-48827HigOct 11, 2024
    risk 0.60cvss 8.8epss 0.03

    An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.

  • CVE-2021-3144CriFeb 27, 2021
    risk 0.60cvss 9.1epss 0.05

    In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

  • CVE-2017-6529HigMar 9, 2017
    risk 0.60cvss 8.8epss 0.03

    An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter.

  • CVE-2026-60053CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued…

  • CVE-2026-41902CriMay 7, 2026
    risk 0.59cvss 9.1epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains…

  • CVE-2025-56643CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to access the system, even after logout. This behavior affects session integrity and may allow…

  • CVE-2024-35049CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.

  • CVE-2024-27455CriFeb 26, 2024
    risk 0.59cvss 9.1epss 0.01

    In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.

  • CVE-2022-2782CriOct 27, 2022
    risk 0.59cvss 9.1epss 0.01

    In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.