CWE-613 · 596 записей
Insufficient Session Expiration
CVE этого класса
597 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2014-2595Proof of concept | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authenticationbarracuda · web application firewall · CWE-613 | Критическая9,8 | — | 16,9 % | 11 февр. 2020 г. |
41В плане | CVE-2020-27422Proof of concept | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the sanuko · time tracker · CWE-613 | Критическая9,8 | — | 7,9 % | 16 нояб. 2020 г. |
40В плане | CVE-2021-24019Proof of concept | An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attackefortinet · forticlient endpoint management server · CWE-613 | Критическая9,8 | — | 3,9 % | 6 окт. 2021 г. |
40В плане | CVE-2020-8234Эксплойта нет | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be gui · edgemax firmware · CWE-613 | Критическая9,8 | — | 3,4 % | 21 авг. 2020 г. |
40В плане | CVE-2020-29667Proof of concept | In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, calanatmservice · m3 atm monitoring system · CWE-613 | Критическая9,8 | — | 3,2 % | 10 дек. 2020 г. |
40В плане | CVE-2016-6545Эксплойта нет | iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each requestieasytec · itrackeasy · CWE-613 | Критическая9,8 | — | 3,0 % | 13 июл. 2018 г. |
40В плане | CVE-2021-3311Эксплойта нет | An issue was discovered in October through build 471.octobercms · october · CWE-613 | Критическая9,8 | — | 2,9 % | 5 февр. 2021 г. |
40В плане | CVE-2018-21018Эксплойта нет | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.joinmastodon · mastodon · CWE-613 | Критическая9,8 | — | 2,6 % | 22 сент. 2019 г. |
40В плане | CVE-2016-11014Эксплойта нет | NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.netgear · jnr1010 firmware · CWE-613 | Критическая9,8 | — | 2,5 % | 16 окт. 2019 г. |
40В плане | CVE-2021-25981Эксплойта нет | Talkyard - Insufficient Session Expirationtalkyard · talkyard · CWE-613 | Критическая9,8 | — | 2,5 % | 3 янв. 2022 г. |
40В плане | CVE-2020-35358Эксплойта нет | DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.domainmod · domainmod · CWE-613 | Критическая9,8 | — | 2,4 % | 15 мар. 2021 г. |
40В плане | CVE-2019-8149Эксплойта нет | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-613 | Критическая9,8 | — | 2,1 % | 5 нояб. 2019 г. |
40В плане | CVE-2020-27739Эксплойта нет | A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in ucitadel · webcit · CWE-613 | Критическая9,8 | — | 1,8 % | 28 окт. 2020 г. |
39Наблюдать | CVE-2021-25992Эксплойта нет | ifme - Insufficient Session Expirationif-me · ifme · CWE-613 | Критическая9,8 | — | 1,6 % | 10 февр. 2022 г. |
39Наблюдать | CVE-2020-27416Эксплойта нет | Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to cmahadiscom · mahavitaran · CWE-613 | Критическая9,8 | — | 1,6 % | 8 дек. 2021 г. |
39Наблюдать | CVE-2020-6649Эксплойта нет | An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexfortinet · fortiisolator · CWE-613 | Критическая9,8 | — | 1,5 % | 8 февр. 2021 г. |
39Наблюдать | CVE-2021-38823Эксплойта нет | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.icehrm · icehrm · CWE-613 | Критическая9,8 | — | 1,5 % | 4 окт. 2021 г. |
39Наблюдать | CVE-2021-37333Эксплойта нет | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.bookingcore · booking core · CWE-613 | Критическая9,8 | — | 1,5 % | 4 окт. 2021 г. |
39Наблюдать | CVE-2018-6634Эксплойта нет | A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain accessparsecgaming · parsec · CWE-613 | Критическая9,8 | — | 1,5 % | 7 мая 2019 г. |
39Наблюдать | CVE-2016-5069Эксплойта нет | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.sierrawireless · aleos firmware · CWE-613 | Критическая9,8 | — | 1,4 % | 9 апр. 2017 г. |
39Наблюдать | CVE-2021-40849Эксплойта нет | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited amahara · mahara · CWE-613 | Критическая9,8 | — | 1,4 % | 3 нояб. 2021 г. |
39Наблюдать | CVE-2022-2713Эксплойта нет | Insufficient Session Expiration in cockpit-hq/cockpitagentejo · cockpit · CWE-613 | Критическая9,8 | — | 1,2 % | 8 авг. 2022 г. |
39Наблюдать | CVE-2021-36330Эксплойта нет | Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.dell · emc streaming data platform · CWE-613 | Критическая9,8 | — | 1,2 % | 30 нояб. 2021 г. |
39Наблюдать | CVE-2020-17474Эксплойта нет | A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary nezkteco · zkbiosecurity server · CWE-613 | Критическая9,8 | — | 1,2 % | 14 авг. 2020 г. |
39Наблюдать | CVE-2015-5171Эксплойта нет | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic cloudfoundry · cf-release · CWE-613 | Критическая9,8 | — | 1,2 % | 24 окт. 2017 г. |
- CVE-2014-259544В плане
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication
КритическаяCVSS 9,8Proof of conceptEPSS 17 %barracuda · web application firewall11 февр. 2020 г.
- CVE-2020-2742241В плане
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s
КритическаяCVSS 9,8Proof of conceptEPSS 8 %anuko · time tracker16 нояб. 2020 г.
- CVE-2021-2401940В плане
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacke
КритическаяCVSS 9,8Proof of conceptEPSS 4 %fortinet · forticlient endpoint management server6 окт. 2021 г.
- CVE-2020-823440В плане
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ui · edgemax firmware21 авг. 2020 г.
- CVE-2020-2966740В плане
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, ca
КритическаяCVSS 9,8Proof of conceptEPSS 3 %lanatmservice · m3 atm monitoring system10 дек. 2020 г.
- CVE-2016-654540В плане
iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ieasytec · itrackeasy13 июл. 2018 г.
- CVE-2021-331140В плане
An issue was discovered in October through build 471.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %octobercms · october5 февр. 2021 г.
- CVE-2018-2101840В плане
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %joinmastodon · mastodon22 сент. 2019 г.
- CVE-2016-1101440В плане
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %netgear · jnr1010 firmware16 окт. 2019 г.
- CVE-2021-2598140В плане
Talkyard - Insufficient Session Expiration
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %talkyard · talkyard3 янв. 2022 г.
- CVE-2020-3535840В плане
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %domainmod · domainmod15 мар. 2021 г.
- CVE-2019-814940В плане
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %magento · magento5 нояб. 2019 г.
- CVE-2020-2773940В плане
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in u
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %citadel · webcit28 окт. 2020 г.
- CVE-2021-2599239Наблюдать
ifme - Insufficient Session Expiration
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %if-me · ifme10 февр. 2022 г.
- CVE-2020-2741639Наблюдать
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mahadiscom · mahavitaran8 дек. 2021 г.
- CVE-2020-664939Наблюдать
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unex
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %fortinet · fortiisolator8 февр. 2021 г.
- CVE-2021-3882339Наблюдать
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %icehrm · icehrm4 окт. 2021 г.
- CVE-2021-3733339Наблюдать
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bookingcore · booking core4 окт. 2021 г.
- CVE-2018-663439Наблюдать
A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %parsecgaming · parsec7 мая 2019 г.
- CVE-2016-506939Наблюдать
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sierrawireless · aleos firmware9 апр. 2017 г.
- CVE-2021-4084939Наблюдать
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited a
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mahara · mahara3 нояб. 2021 г.
- CVE-2022-271339Наблюдать
Insufficient Session Expiration in cockpit-hq/cockpit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %agentejo · cockpit8 авг. 2022 г.
- CVE-2021-3633039Наблюдать
Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · emc streaming data platform30 нояб. 2021 г.
- CVE-2020-1747439Наблюдать
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary ne
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zkteco · zkbiosecurity server14 авг. 2020 г.
- CVE-2015-517139Наблюдать
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudfoundry · cf-release24 окт. 2017 г.