Metrics
Affected Vendors & Products
Solution
Upgrade to 2.0.3 or later, where Web UI enforces forced logout when role changes occur.
Workaround
On earlier versions, administrators should manually log out users when changing access rights.
Wed, 10 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 10 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration. | |
Title | Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One | |
Weaknesses | CWE-613 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AxxonSoft
Published:
Updated: 2025-09-10T13:24:30.194Z
Reserved: 2025-09-10T12:35:13.351Z
Link: CVE-2025-10223

Updated: 2025-09-10T13:23:43.235Z

Status : Received
Published: 2025-09-10T13:15:36.003
Modified: 2025-09-10T13:15:36.003
Link: CVE-2025-10223

No data.

No data.