Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27539 Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.
Fixes

Solution

Upgrade to Axxon One with OpenSSL 3.0.13 or later, where session key management logic was refactored to avoid unsafe memory reallocations.


Workaround

No workaround given by the vendor.

History

Mon, 06 Oct 2025 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:windows:*:*

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Axxonsoft
Axxonsoft axxon One
Microsoft
Microsoft windows
Vendors & Products Axxonsoft
Axxonsoft axxon One
Microsoft
Microsoft windows

Wed, 10 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.
Title Incorrect Memory Allocation in OpenSSL-Based Session Module in AxxonSoft Axxon One
Weaknesses CWE-119
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AxxonSoft

Published:

Updated: 2025-09-10T13:12:27.743Z

Reserved: 2025-09-10T12:37:02.143Z

Link: CVE-2025-10225

cve-icon Vulnrichment

Updated: 2025-09-10T13:12:21.133Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-10T13:15:36.430

Modified: 2025-10-06T17:29:42.650

Link: CVE-2025-10225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-12T09:11:32Z