Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27541 | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration. |
Solution
Upgrade to 2.0.3 or later, where Web UI enforces forced logout when role changes occur.
Workaround
On earlier versions, administrators should manually log out users when changing access rights.
Wed, 08 Oct 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration. | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration. |
| Title | Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One | Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One (C-Werk) |
Mon, 06 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:windows:*:* |
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axxonsoft
Axxonsoft axxon One Microsoft Microsoft windows |
|
| Vendors & Products |
Axxonsoft
Axxonsoft axxon One Microsoft Microsoft windows |
Wed, 10 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration. | |
| Title | Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AxxonSoft
Published:
Updated: 2025-10-08T11:49:37.530Z
Reserved: 2025-09-10T12:35:13.351Z
Link: CVE-2025-10223
Updated: 2025-09-10T13:23:43.235Z
Status : Modified
Published: 2025-09-10T13:15:36.003
Modified: 2025-10-08T12:15:35.013
Link: CVE-2025-10223
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:27Z
EUVD