← Back
CWE-613

568 CVEs • Abstraction: Base

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

JSON object

Loading...

CVEs (568)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Prominent
1Multiflex M10a Controller Firmware
May 13, 2026
Oct 17, 2017
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's session is available for an extended period beyond the last activity, allowing an attacker to reuse...Show more
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's session is available for an extended period beyond the last activity, allowing an attacker to reuse an old session for authorization.Show less
1Simplesamlphp
1Simplesamlphp
May 13, 2026
Aug 29, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.
1Openproject
1Openproject
May 13, 2026
Jul 26, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.
1Milwaukee
1One Key
May 13, 2026
Jun 20, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.
1Moxa
1Awk 3131a Firmware
May 13, 2026
Apr 13, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes...Show more
An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the web application has been idle for 300 seconds.Show less
1Sierrawireless
1Aleos Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.
1Dnatools
1Dnalims
May 13, 2026
Mar 9, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter.
2Debian
F5
2Debian Linux
Nginx
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain...Show more
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.Show less