CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

533 vulnerabilities with CWE-613
CVE-2018-14345 HIGH
SDDM <0.17.0 - Privilege Escalation
CVSS 7.5
CVE-2018-11386 MEDIUM
Symfony HttpFoundation 2.7.0-2.7.47 - Denial of Service via PDOSessionHandler
CVSS 5.9
CVE-2018-10990 HIGH
Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 - Insufficient Session Expiration
CVSS 8.0
CVE-2018-7758 MEDIUM
Schneider Electric's MiCOM Px4x - DoS
CVSS 6.5
CVE-2018-0152 HIGH
Cisco IOS XE - Insufficient Session Expiration in Web UI
CVSS 8.8
CVE-2018-5438 MEDIUM
Philips ISCV <2.3.0 - Privilege Escalation
CVSS 6.3
CVE-2018-1195 HIGH
Cloud Controller <1.46.0 - Auth Bypass
CVSS 8.8
CVE-2017-18905 MEDIUM
Mattermost Server <4.0.0-3.9.2 - Info Disclosure
CVSS 5.3
CVE-2017-3966 MEDIUM
McAfee Network Security Manager < 8.2.7.42.2 - Session Fixation via Exposed Session Token
CVSS 6.4
CVE-2017-12191 HIGH
Red Hat CloudForms - Improper Access Control via VMware Shared Account
CVSS 7.4
CVE-2017-15653 HIGH
Asus asuswrt <= 3.0.0.4.380.7743 - Unauthenticated Session Hijacking via User-Agent String
CVSS 8.8
CVE-2017-1693 MEDIUM
IBM Integration Bus <10.0 - Session Hijacking
CVSS 5.6
CVE-2017-1000136 MEDIUM
Mahara <1.8.6, <1.9.4, <1.10.1, <15.04.0 - Info Disclosure
CVSS 6.5
CVE-2017-1000135 MEDIUM
Mahara <1.8.7, <1.9.5, <1.10.3, <15.04.0 - Privilege Escalation
CVSS 6.5
CVE-2017-1000131 MEDIUM
Mahara <15.04.8, 15.10 <15.10.4, 16.04 <16.04.2 - Info Disclosure
CVSS 6.5
CVE-2017-12159 HIGH
Keycloak - Cross-Site Request Forgery
CVSS 7.5
CVE-2017-6145 HIGH
F5 BIG-IP 12.0.0-12.1.2 and 13.0.0 - Insufficient Session Expiration via iControl REST Cookie Conversion
CVSS 7.3
CVE-2017-14007 MEDIUM
ProMinent MultiFLEX M10a - Info Disclosure
CVSS 5.6
CVE-2017-12867 MEDIUM
SimpleSAMLphp < 1.14.14 - Insufficient Session Expiration via Time Offset Manipulation
CVSS 5.9
CVE-2017-11667 HIGH
OpenProject <6.1.6 & <7.0.3 - Info Disclosure
CVSS 8.1
CVE-2017-3215 MEDIUM
Milwaukee ONE-KEY - Insufficient Session Expiration
CVSS 5.3
CVE-2017-6529 HIGH
dnaTools dnaLIMS 4-2015s13 - Session Hijacking via UID Parameter Guessing
CVSS 8.8
CVE-2016-20007 HIGH
REST/JSON project 7.x-1.x - Info Disclosure
CVSS 7.5
CVE-2016-11058 HIGH
NETGEAR genie < 2.4.34 - Insufficient Session Expiration via Hard-coded API Keys
CVSS 7.5
CVE-2016-11014 CRITICAL
NETGEAR JNR1010 Firmware < 1.0.0.32 - Insufficient Session Expiration via Auth Cookie
CVSS 9.8
Details
Vulnerabilities 533