Vulnerabilities > Insufficient Session Expiration

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-1000814 Insufficient Session Expiration vulnerability in Aiohttp-Session Project Aiohttp-Session
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan.
network
low complexity
aiohttp-session-project CWE-613
6.5
2018-08-30 CVE-2016-0234 Insufficient Session Expiration vulnerability in IBM Openpages GRC Platform
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser.
local
low complexity
ibm CWE-613
3.3
2018-08-14 CVE-2018-2451 Insufficient Session Expiration vulnerability in SAP Hana Extended Application Services 1.0
XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity.
network
high complexity
sap CWE-613
6.6
2018-07-17 CVE-2018-14345 Insufficient Session Expiration vulnerability in Sddm Project Sddm
An issue was discovered in SDDM through 0.17.0.
network
high complexity
sddm-project CWE-613
7.5
2018-06-13 CVE-2018-11386 Insufficient Session Expiration vulnerability in multiple products
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11.
network
high complexity
sensiolabs debian CWE-613
5.9
2018-05-14 CVE-2018-10990 Insufficient Session Expiration vulnerability in Commscope Arris Tg1682G Firmware 9.1.103J6
On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state on the device related to the validity of the "credential" cookie, which might make it easier for attackers to obtain access at a later time (e.g., "at least for a few minutes").
network
high complexity
commscope CWE-613
8.0
2018-04-18 CVE-2018-7758 Insufficient Session Expiration vulnerability in Schneider-Electric products
A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.
low complexity
schneider-electric CWE-613
6.5
2018-04-04 CVE-2017-3966 Insufficient Session Expiration vulnerability in Mcafee Network Security Manager
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL.
network
low complexity
mcafee CWE-613
6.3
2018-03-28 CVE-2018-0152 Insufficient Session Expiration vulnerability in Cisco IOS XE 16.1.1
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device.
network
low complexity
cisco CWE-613
8.8
2018-03-20 CVE-2018-5438 Insufficient Session Expiration vulnerability in Philips Intellispace Cardiovascular 2.3.0
Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker could reuse the session of a previously logged in user.
local
high complexity
philips CWE-613
6.3