Cyber Posture

CWE · MITRE source

CWE-613Insufficient Session Expiration

Abstraction: Base · CVEs in our corpus: 513

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (8)AI

Control Title Family Why it addresses this CWE
AC-11Device LockACLocks the device (typically after inactivity) until re-authentication, addressing insufficient session expiration by preventing indefinite access.
AC-12Session TerminationACAutomatically terminating sessions after a defined period directly enforces session expiration, preventing indefinite session lifetimes that attackers can exploit.
SC-10Network DisconnectSCDirectly enforces termination of network sessions after inactivity or end-of-session, preventing indefinite session lifetime.
SC-45System Time SynchronizationSCConsistent clocks across systems allow session expiration and timeout enforcement to function as intended in distributed environments.
SI-14Non-persistenceSIWhen the non-persistent artifact is a session or connection, mandatory termination implements the missing expiration that CWE-613 describes.
SI-21Information RefreshSITimed refresh of session-related information or on-demand generation plus deletion implements proper session expiration.
IA-11Re-authenticationIARe-authentication after inactivity or time-based triggers prevents indefinite use of potentially hijacked or stale sessions.
MA-4Nonlocal MaintenanceMATerminating sessions and network connections upon completion prevents insufficient session expiration.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2014-25955.49.80.57472020-02-12
CVE-2020-274222.69.80.10692020-11-16
CVE-2024-488272.68.80.14752024-10-11
CVE-2021-240192.58.10.15192021-10-06
CVE-2020-296672.29.80.04442020-12-10
CVE-2018-210182.19.80.01642019-09-22
CVE-2020-82342.19.80.01802020-08-21
CVE-2020-277392.19.80.02232020-10-28
CVE-2021-33112.19.80.01522021-02-05
CVE-2021-31442.19.10.05482021-02-27
CVE-2021-259812.19.80.02102022-01-03
CVE-2017-65292.08.80.04482017-03-09
CVE-2016-50692.09.80.00032017-04-10
CVE-2015-51712.09.80.00482017-10-24
CVE-2016-65452.09.80.00952018-07-13
CVE-2018-66342.09.80.00522019-05-07
CVE-2016-110142.09.80.00442019-10-16
CVE-2019-81492.09.80.00422019-11-06
CVE-2020-174742.09.80.00382020-08-14
CVE-2020-66492.09.80.00412021-02-08
CVE-2020-353582.09.80.01482021-03-15
CVE-2021-373332.09.80.00382021-10-04
CVE-2021-388232.09.80.00382021-10-04
CVE-2021-408492.09.80.00432021-11-03
CVE-2021-259792.09.80.00362021-11-08