An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the to
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which int
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted a
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Provid
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue
In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token wh
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-
On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend ser
An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e
An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminat
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was del
A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to
The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the sessi
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session o
Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an at
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via
Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could al
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected a
Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access t
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have
@festify/secure-session creates a secure stateless cookie session for Fastify. At the end of the request handling, it wi
@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from th
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high p
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, maki
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after d
IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation
Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still
IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impers
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modifi
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authentic
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authent
The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex
Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticat
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to
An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their passw
A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid”
Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier a
IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated use
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens functi
Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A rem
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to ver
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session ex
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started