CWE-613
Insufficient Session Expiration
Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Parent Weaknesses (ChildOf)
Related Weaknesses
Common Consequences
Scope
Impact
Bypass Protection Mechanism
Potential Mitigations
Set sessions/credentials expiration date.
CVE-2025-46344JavaScript SDK does not set an expiration time for JWE tokens related to a session
CVE-2024-8888Web interface for a power quality analyzer uses tokens without an expiration date
CVE-2024-35206network traffic analyzer for PROFINET networks does not expire sessions
CVE-2024-27782AI/ML monitor for IT operations allows re-use of old session tokens due to insufficient session expiration
Applicable Platforms
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now