CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

576 vulnerabilities with CWE-613
CVE-2024-5995 HIGH
Soar Cloud HR Portal - Info Disclosure
CVSS 8.8
CVE-2024-36523 MEDIUM
Wvp GB28181 Pro 2.0 - Info Disclosure
CVSS 6.5
CVE-2024-35206 HIGH
SINEC Traffic Analyzer < 1.2 - Insufficient Session Expiration
CVSS 7.7
CVE-2024-4680 HIGH
zenml 0.56.3 - Insufficient Session Expiration after Password Change
CVSS 8.8
CVE-2024-35220 HIGH
fastify/session < 10.9.0 - Insufficient Session Expiration via Cookie Restore
CVSS 7.4
CVE-2024-35050 HIGH
SurveyKing 1.3.1 - Privilege Escalation via Reused Session ID
CVSS 8.8
CVE-2024-35049 CRITICAL
SurveyKing 1.3.1 - Insufficient Session Expiration
CVSS 9.1
CVE-2024-35048 MEDIUM
SurveyKing 1.3.1 - Insufficient Session Expiration
CVSS 4.3
CVE-2024-34709 MEDIUM
Directus < 10.11.0 - Insufficient Session Expiration via JWT Token
CVSS 5.4
CVE-2024-34092 HIGH
Archer Platform <2024.04 - Privilege Escalation
CVSS 8.8
CVE-2024-29402 MEDIUM
cskefu v7 - Insufficient Session Expiration
CVSS 4.3
CVE-2024-22358 MEDIUM
IBM UrbanCode Deploy <7.3.2.4 - Privilege Escalation
CVSS 6.3
CVE-2024-31999 HIGH
@festify/secure-session - Info Disclosure
CVSS 7.4
CVE-2024-31995 MEDIUM
@digitalbazaar/zcap <9.0.1 - Info Disclosure
CVSS 4.3
CVE-2024-30262 MEDIUM
Contao < 4.13.40 - Insufficient Session Expiration via Remember-Me Tokens
CVSS 5.9
CVE-2024-31447 MEDIUM
Shopware 6.3.5.0-6.5.8.7 - Insufficient Session Expiration via Store-API Logout
CVSS 5.3
CVE-2024-25954 MEDIUM
Dell PowerScale OneFS 9.5.0.x-9.7.0.x - Unauthenticated Denial of Service via Insufficient Session Expiration
CVSS 5.3
CVE-2024-29401 CRITICAL
xzs-mysql 3.8 - Insufficient Session Expiration
CVSS 9.8
CVE-2024-1623 HIGH
Sagemcom F@ST 3686 Firmware < 3.709.2 - Insufficient Session Expiration in Login/Logout Handler
CVSS 7.7
CVE-2024-20301 MEDIUM
Cisco Duo Authentication For Windows Logon And RDP < 4.3.0 - Insufficient Session Expiration
CVSS 6.2
CVE-2024-1900 MEDIUM
Devolutions Server < 2023.3.16.0 - Authenticated Insufficient Session Expiration in Identity Provider Flow
CVSS 5.5
CVE-2024-21722 MEDIUM
Joomla! 3.2.0-3.10.14 - Insufficient Session Expiration in MFA Management
CVSS 6.3
CVE-2024-22543 MEDIUM
Linksys Router E1700 <1.0.04 - Privilege Escalation
CVSS 6.1
CVE-2024-27455 CRITICAL
Bentley ALIM Web - Unauthenticated Session Token Exposure via File Download
CVSS 9.1
CVE-2024-21492 MEDIUM
caddy-security - Insufficient Session Expiration via Logout Endpoint
CVSS 4.8
Details
Vulnerabilities 576