CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
533 vulnerabilities with CWE-613
CVE-2018-14345
HIGH
SDDM <0.17.0 - Privilege Escalation
CVSS 7.5
CVE-2018-11386
MEDIUM
Symfony HttpFoundation 2.7.0-2.7.47 - Denial of Service via PDOSessionHandler
CVSS 5.9
CVE-2018-10990
HIGH
Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 - Insufficient Session Expiration
CVSS 8.0
CVE-2018-7758
MEDIUM
Schneider Electric's MiCOM Px4x - DoS
CVSS 6.5
CVE-2018-0152
HIGH
Cisco IOS XE - Insufficient Session Expiration in Web UI
CVSS 8.8
CVE-2018-5438
MEDIUM
Philips ISCV <2.3.0 - Privilege Escalation
CVSS 6.3
CVE-2018-1195
HIGH
Cloud Controller <1.46.0 - Auth Bypass
CVSS 8.8
CVE-2017-18905
MEDIUM
Mattermost Server <4.0.0-3.9.2 - Info Disclosure
CVSS 5.3
CVE-2017-3966
MEDIUM
McAfee Network Security Manager < 8.2.7.42.2 - Session Fixation via Exposed Session Token
CVSS 6.4
CVE-2017-12191
HIGH
Red Hat CloudForms - Improper Access Control via VMware Shared Account
CVSS 7.4
CVE-2017-15653
HIGH
Asus asuswrt <= 3.0.0.4.380.7743 - Unauthenticated Session Hijacking via User-Agent String
CVSS 8.8
CVE-2017-1693
MEDIUM
IBM Integration Bus <10.0 - Session Hijacking
CVSS 5.6
CVE-2017-1000136
MEDIUM
Mahara <1.8.6, <1.9.4, <1.10.1, <15.04.0 - Info Disclosure
CVSS 6.5
CVE-2017-1000135
MEDIUM
Mahara <1.8.7, <1.9.5, <1.10.3, <15.04.0 - Privilege Escalation
CVSS 6.5
CVE-2017-1000131
MEDIUM
Mahara <15.04.8, 15.10 <15.10.4, 16.04 <16.04.2 - Info Disclosure
CVSS 6.5
CVE-2017-12159
HIGH
Keycloak - Cross-Site Request Forgery
CVSS 7.5
CVE-2017-6145
HIGH
F5 BIG-IP 12.0.0-12.1.2 and 13.0.0 - Insufficient Session Expiration via iControl REST Cookie Conversion
CVSS 7.3
CVE-2017-14007
MEDIUM
ProMinent MultiFLEX M10a - Info Disclosure
CVSS 5.6
CVE-2017-12867
MEDIUM
SimpleSAMLphp < 1.14.14 - Insufficient Session Expiration via Time Offset Manipulation
CVSS 5.9
CVE-2017-11667
HIGH
OpenProject <6.1.6 & <7.0.3 - Info Disclosure
CVSS 8.1
CVE-2017-3215
MEDIUM
Milwaukee ONE-KEY - Insufficient Session Expiration
CVSS 5.3
CVE-2017-6529
HIGH
dnaTools dnaLIMS 4-2015s13 - Session Hijacking via UID Parameter Guessing
CVSS 8.8
CVE-2016-20007
HIGH
REST/JSON project 7.x-1.x - Info Disclosure
CVSS 7.5
CVE-2016-11058
HIGH
NETGEAR genie < 2.4.34 - Insufficient Session Expiration via Hard-coded API Keys
CVSS 7.5
CVE-2016-11014
CRITICAL
NETGEAR JNR1010 Firmware < 1.0.0.32 - Insufficient Session Expiration via Auth Cookie
CVSS 9.8
Details
Vulnerabilities
533