VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 6 of 31
  • CVE-2025-42602HigApr 23, 2025
    risk 0.53cvss epss 0.00

    This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints of authentication process. A remote attacker could exploit this vulnerability by intercepting and manipulating the responses through API request body…

  • CVE-2025-24973CriFeb 11, 2025
    risk 0.53cvss 9.3epss 0.00

    Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication credentials remain in cookies even after a user has explicitly logged out, which may…

  • CVE-2024-27782HigJul 9, 2024
    risk 0.53cvss 8.1epss 0.01

    Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.

  • CVE-2023-33303HigOct 13, 2023
    risk 0.53cvss 8.1epss 0.00

    A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request

  • CVE-2023-40537HigOct 10, 2023
    risk 0.53cvss 8.1epss 0.00

    An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2022-35728HigAug 4, 2022
    risk 0.53cvss 8.1epss 0.01

    In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited…

  • CVE-2021-36330HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.

  • CVE-2021-42545HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.

  • CVE-2021-34739HigNov 4, 2021
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected…

  • CVE-2021-24019HigOct 6, 2021
    risk 0.53cvss 8.1epss 0.04

    An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other,…

  • CVE-2020-23140HigNov 9, 2020
    risk 0.53cvss 8.1epss 0.01

    Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.

  • CVE-2020-13299HigSep 14, 2020
    risk 0.53cvss 8.1epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

  • CVE-2020-6644HigJun 22, 2020
    risk 0.53cvss 8.1epss 0.01

    An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, hypothetical attacks.

  • CVE-2017-11667HigJul 26, 2017
    risk 0.53cvss 8.1epss 0.01

    OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.

  • CVE-2016-8712HigApr 13, 2017
    risk 0.53cvss 8.1epss 0.01

    An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the web application has been idle for 300…

  • CVE-2026-56750CriAug 13, 2026
    risk 0.52cvss 9.1epss 0.00

    Gitea Remember-Me Token Theft Not Invalidating Attacker Session

  • CVE-2026-53776CriJun 16, 2026
    risk 0.52cvss 9.1epss 0.00

    Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a…

  • CVE-2025-57735CriApr 9, 2026
    risk 0.52cvss 9.1epss 0.01

    When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about…

  • CVE-2026-27575CriFeb 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes…

  • CVE-2025-2185HigApr 25, 2025
    risk 0.52cvss 8.0epss 0.00

    ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming…