VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 21 of 31
  • CVE-2025-4643MedAug 29, 2025
    risk 0.34cvss epss 0.00

    Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed). This issue has been…

  • CVE-2024-50562MedJun 10, 2025
    risk 0.34cvss 4.8epss 0.01

    An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again,…

  • CVE-2025-2596MedMar 26, 2025
    risk 0.34cvss 5.3epss 0.00

    Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)

  • CVE-2024-45462MedOct 16, 2024
    risk 0.34cvss 6.3epss 0.00

    The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of the backend service. An attacker that has access to a user's browser can use an unexpired session to gain access to resources owned…

  • CVE-2024-23586MedSep 27, 2024
    risk 0.34cvss 5.3epss 0.00

    HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

  • CVE-2022-32759MedJul 25, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565.

  • CVE-2024-25954MedMar 28, 2024
    risk 0.34cvss 5.3epss 0.01

    Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2023-39695MedOct 31, 2023
    risk 0.34cvss 5.3epss 0.00

    Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and data after logging out.

  • CVE-2021-20581MedOct 17, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.

  • CVE-2022-24895MedFeb 3, 2023
    risk 0.34cvss 6.3epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because this does not clear CSRF tokens upon login,…

  • CVE-2022-24732MedMar 9, 2022
    risk 0.34cvss 6.3epss 0.00

    Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired…

  • CVE-2025-12317MedAug 6, 2026
    risk 0.33cvss 5.0epss 0.00

    When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have…

  • CVE-2026-55423MedJun 23, 2026
    risk 0.33cvss 6.1epss 0.00

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.

  • CVE-2026-24667MedFeb 3, 2026
    risk 0.33cvss 5.0epss 0.00

    The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens to remain valid, potentially enabling unauthorized continued…

  • CVE-2025-62329MedDec 16, 2025
    risk 0.33cvss 5.0epss 0.00

    HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.

  • CVE-2025-36360MedDec 15, 2025
    risk 0.33cvss 5.0epss 0.00

    IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a…

  • CVE-2025-62781MedOct 27, 2025
    risk 0.33cvss 5.0epss 0.00

    PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are terminated, except for the currently active one. However, the…

  • CVE-2024-8995MedAug 6, 2026
    risk 0.32cvss 4.9epss 0.00

    Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated…

  • CVE-2026-14227MedJul 30, 2026
    risk 0.32cvss 4.9epss 0.00

    An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a…

  • CVE-2026-45005MedMay 11, 2026
    risk 0.32cvss 6.0epss 0.00

    OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured…