CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
576 vulnerabilities with CWE-613
CVE-2017-3966
MEDIUM
McAfee Network Security Manager < 8.2.7.42.2 - Session Fixation via Exposed Session Token
CVSS 6.4
CVE-2017-12191
HIGH
Red Hat CloudForms - Improper Access Control via VMware Shared Account
CVSS 7.4
CVE-2017-15653
HIGH
Asus asuswrt <= 3.0.0.4.380.7743 - Unauthenticated Session Hijacking via User-Agent String
CVSS 8.8
CVE-2017-1693
MEDIUM
IBM Integration Bus <10.0 - Session Hijacking
CVSS 5.6
CVE-2017-1000136
MEDIUM
Mahara <1.8.6, <1.9.4, <1.10.1, <15.04.0 - Info Disclosure
CVSS 6.5
CVE-2017-1000135
MEDIUM
Mahara <1.8.7, <1.9.5, <1.10.3, <15.04.0 - Privilege Escalation
CVSS 6.5
CVE-2017-1000131
MEDIUM
Mahara <15.04.8, 15.10 <15.10.4, 16.04 <16.04.2 - Info Disclosure
CVSS 6.5
CVE-2017-12159
HIGH
Keycloak - Cross-Site Request Forgery
CVSS 7.5
CVE-2017-6145
HIGH
F5 BIG-IP 12.0.0-12.1.2 and 13.0.0 - Insufficient Session Expiration via iControl REST Cookie Conversion
CVSS 7.3
CVE-2017-14007
MEDIUM
ProMinent MultiFLEX M10a - Info Disclosure
CVSS 5.6
CVE-2017-12867
MEDIUM
SimpleSAMLphp < 1.14.14 - Insufficient Session Expiration via Time Offset Manipulation
CVSS 5.9
CVE-2017-11667
HIGH
OpenProject <6.1.6 & <7.0.3 - Info Disclosure
CVSS 8.1
CVE-2017-3215
MEDIUM
Milwaukee ONE-KEY - Insufficient Session Expiration
CVSS 5.3
CVE-2017-6529
HIGH
dnaTools dnaLIMS 4-2015s13 - Session Hijacking via UID Parameter Guessing
CVSS 8.8
CVE-2016-20007
HIGH
REST/JSON project 7.x-1.x - Info Disclosure
CVSS 7.5
CVE-2016-11058
HIGH
NETGEAR genie < 2.4.34 - Insufficient Session Expiration via Hard-coded API Keys
CVSS 7.5
CVE-2016-11014
CRITICAL
NETGEAR JNR1010 Firmware < 1.0.0.32 - Insufficient Session Expiration via Auth Cookie
CVSS 9.8
CVE-2016-0234
MEDIUM
IBM OpenPages GRC Platform <7.3 - Info Disclosure
CVSS 4.0
CVE-2016-6545
CRITICAL
iTrack Easy - Info Disclosure
CVSS 9.8
CVE-2016-8712
HIGH
Moxa AWK-3131A Wireless AP <1.1 - RCE
CVSS 8.1
CVE-2016-5069
CRITICAL
Sierra Wireless GX 440 ALEOS Firmware 4.3.2 - Insufficient Session Expiration via URL Session Tokens
CVSS 9.8
CVE-2015-5171
CRITICAL
Cloudfoundry Cf-release < 216 - Insufficient Session Expiration
CVSS 9.8
CVE-2014-2595
CRITICAL
Barracuda WAF 7.8.1.013 - Auth Bypass
CVSS 9.8
CVE-2014-3616
nginx 0.5.6-1.7.4 - Insufficient Session Expiration via Shared SSL Session Cache
CVE-2013-0335
HIGH
OpenStack Compute (Nova) Essex, Folsom, and Grizzly - Authenticated VM Access via VNC Token Reuse
CVSS 7.6
Details
Vulnerabilities
576