No analysis available yet.
Vendor Solution
Upgrade to Axxon One 2.0.2 (C-Werk) or later, where the diagnostic export tool has been refactored to exclude licensing-related sensitive variables.
Vendor Workaround
Delete previously generated diagnostic files that may contain sensitive information. Limit access to diagnostic exports to trusted administrators only.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27542 | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool. |
Wed, 08 Oct 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool. | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool. |
Mon, 06 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:*:*:* |
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axxonsoft
Axxonsoft axxon One Microsoft Microsoft windows |
|
| Vendors & Products |
Axxonsoft
Axxonsoft axxon One Microsoft Microsoft windows |
Wed, 10 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool. | |
| Title | Sensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMS | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AxxonSoft
Published:
Updated: 2025-10-08T11:46:46.982Z
Reserved: 2025-09-10T12:33:59.159Z
Link: CVE-2025-10222
Updated: 2025-09-10T13:44:03.257Z
Status : Modified
Published: 2025-09-10T13:15:35.793
Modified: 2025-10-08T12:15:34.840
Link: CVE-2025-10222
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:30Z
EUVD