Cyber Resilience

CWE · MITRE source

CWE-613Insufficient Session Expiration

Abstraction: Base · CVEs in our corpus: 591

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Last updated: 20 August 2026 13:14 UTC

OWASP Top 10 for Web (2025)

This weakness contributes to A07:2025 Authentication Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (8)AI-assisted

Control Title Family Why it addresses this CWE
AC-11Device LockACLocks the device (typically after inactivity) until re-authentication, addressing insufficient session expiration by preventing indefinite access.
AC-12Session TerminationACAutomatically terminating sessions after a defined period directly enforces session expiration, preventing indefinite session lifetimes that attackers can exploit.
SC-10Network DisconnectSCDirectly enforces termination of network sessions after inactivity or end-of-session, preventing indefinite session lifetime.
SC-45System Time SynchronizationSCConsistent clocks across systems allow session expiration and timeout enforcement to function as intended in distributed environments.
SI-14Non-persistenceSIWhen the non-persistent artifact is a session or connection, mandatory termination implements the missing expiration that CWE-613 describes.
SI-21Information RefreshSITimed refresh of session-related information or on-demand generation plus deletion implements proper session expiration.
IA-11Re-authenticationIARe-authentication after inactivity or time-based triggers prevents indefinite use of potentially hijacked or stale sessions.
MA-4Nonlocal MaintenanceMATerminating sessions and network connections upon completion prevents insufficient session expiration.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2014-2595 8.49.80.16872020-02-12
CVE-2020-27422 8.19.80.07862020-11-16
CVE-2016-6545 7.89.80.03062018-07-13
CVE-2020-8234 7.89.80.03412020-08-21
CVE-2020-29667 7.89.80.03192020-12-10
CVE-2021-3311 7.89.80.02902021-02-05
CVE-2018-21018 7.79.80.02562019-09-22
CVE-2016-11014 7.79.80.02542019-10-16
CVE-2019-8149 7.79.80.02142019-11-06
CVE-2020-35358 7.79.80.02432021-03-15
CVE-2021-25981 7.79.80.02462022-01-03
CVE-2016-5069 7.69.80.01352017-04-10
CVE-2018-6634 7.69.80.01462019-05-07
CVE-2020-27739 7.69.80.01842020-10-28
CVE-2020-6649 7.69.80.01522021-02-08
CVE-2021-37333 7.69.80.01472021-10-04
CVE-2021-38823 7.69.80.01502021-10-04
CVE-2021-40849 7.69.80.01312021-11-03
CVE-2020-27416 7.69.80.01592021-12-08
CVE-2021-25992 7.69.80.01602022-02-10
CVE-2015-5171 7.59.80.01172017-10-24
CVE-2020-17474 7.59.80.01182020-08-14
CVE-2021-3144 7.59.10.05242021-02-27
CVE-2021-25979 7.59.80.01102021-11-08
CVE-2021-22820 7.59.80.01082022-01-28