CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
576 vulnerabilities with CWE-613
CVE-2019-5531
MEDIUM
VMware ESXi and vCenter Server - Insufficient Session Expiration
CVSS 5.4
CVE-2019-14826
MEDIUM
FreeIPA >= 4.5.0 - Insufficient Session Expiration
CVSS 4.4
CVE-2019-16133
MEDIUM
Eteams OA <4.0.34 - Info Disclosure
CVSS 6.5
CVE-2019-5638
HIGH
Rapid7 Nexpose <= 6.5.50 - Insufficient Session Expiration
CVSS 8.7
CVE-2019-2386
HIGH
MongoDB Server <4.0.9, <3.6.13, <3.4.22 - Info Disclosure
CVSS 7.1
CVE-2019-7280
HIGH
Prima Systems FlexAir <2.3.38 - Info Disclosure
CVSS 8.8
CVE-2019-6584
HIGH
SIEMENS LOGO!8 - Privilege Escalation
CVSS 8.8
CVE-2019-3790
MEDIUM
Pivotal Ops Manager Authenticated Session Fixation via Refresh Token Bypass
CVSS 6.1
CVE-2019-7215
MEDIUM
Progress Sitefinity 10.1.6536 - Info Disclosure
CVSS 6.5
CVE-2019-4072
MEDIUM
IBM Spectrum Control 5.2.1-5.2.17 - Insufficient Session Expiration
CVSS 6.3
CVE-2019-1003049
HIGH
Jenkins < 2.164.1 and < 2.171 - Insufficient Session Expiration
CVSS 8.1
CVE-2019-0015
MEDIUM
Junos OS on SRX Series Insufficient Session Expiration
CVSS 5.4
CVE-2018-21018
CRITICAL
Mastodon < 2.6.3 - Insufficient Session Expiration
CVSS 9.8
CVE-2018-6634
CRITICAL
Parsec Windows 142-0 and Linux Ubuntu 16.04 LTS Desktop Build 142-1 - Insufficient Session Expiration
CVSS 9.8
CVE-2018-1000814
MEDIUM
aio-libs aiohttp-session <=2.6.0 - Non-Expiring Sessions
CVSS 6.5
CVE-2018-1127
MEDIUM
Red Hat Gluster Storage <3.4.0 - Info Disclosure
CVSS 4.2
CVE-2018-2451
MEDIUM
SAP HANA Extended Application Services - Insufficient Session Expiration
CVSS 6.6
CVE-2018-14345
HIGH
SDDM <0.17.0 - Privilege Escalation
CVSS 7.5
CVE-2018-11386
MEDIUM
Symfony HttpFoundation 2.7.0-2.7.47 - Denial of Service via PDOSessionHandler
CVSS 5.9
CVE-2018-10990
HIGH
Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 - Insufficient Session Expiration
CVSS 8.0
CVE-2018-7758
MEDIUM
Schneider Electric's MiCOM Px4x - DoS
CVSS 6.5
CVE-2018-0152
HIGH
Cisco IOS XE - Insufficient Session Expiration in Web UI
CVSS 8.8
CVE-2018-5438
MEDIUM
Philips ISCV <2.3.0 - Privilege Escalation
CVSS 6.3
CVE-2018-1195
HIGH
Cloud Controller <1.46.0 - Auth Bypass
CVSS 8.8
CVE-2017-18905
MEDIUM
Mattermost Server <4.0.0-3.9.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
576