CWE-613
568 CVEs • Abstraction: Base
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
CVEs (568)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Prominent 1Multiflex M10a Controller Firmware May 13, 2026 Oct 17, 2017 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's session is available for an extended period beyond the last activity, allowing an attacker to reuse...Show more |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Aug 29, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset. |
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session. |
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions. |
An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes...Show more |
1Sierrawireless 1Aleos Firmware May 13, 2026 Apr 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL. |
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter. |
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain...Show more |