Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-27541 | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration. |
Solution
Upgrade to 2.0.3 or later, where Web UI enforces forced logout when role changes occur.
Workaround
On earlier versions, administrators should manually log out users when changing access rights.
Mon, 06 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:windows:*:* |
Fri, 12 Sep 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Axxonsoft
Axxonsoft axxon One Microsoft Microsoft windows |
|
Vendors & Products |
Axxonsoft
Axxonsoft axxon One Microsoft Microsoft windows |
Wed, 10 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 10 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration. | |
Title | Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One | |
Weaknesses | CWE-613 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AxxonSoft
Published:
Updated: 2025-09-10T13:24:30.194Z
Reserved: 2025-09-10T12:35:13.351Z
Link: CVE-2025-10223

Updated: 2025-09-10T13:23:43.235Z

Status : Analyzed
Published: 2025-09-10T13:15:36.003
Modified: 2025-10-06T18:06:54.690
Link: CVE-2025-10223

No data.

Updated: 2025-09-12T09:11:27Z