Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27537 Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Fixes

Solution

Upgrade to Axxon One (C-Werk) 2.0.8 or later, where AES-256 encryption of object archive is implemented.


Workaround

No workaround given by the vendor.

History

Wed, 08 Oct 2025 12:15:00 +0000

Type Values Removed Values Added
Description Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest. Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Title Lack of Encryption in Object Archive in AxxonSoft Axxon One before 2.0.8 Lack of Encryption in Object Archive in AxxonSoft Axxon One (C-Werk) before 2.0.8

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Axxonsoft
Axxonsoft axxon One
Linux
Linux linux
Microsoft
Microsoft windows
Vendors & Products Axxonsoft
Axxonsoft axxon One
Linux
Linux linux
Microsoft
Microsoft windows

Wed, 10 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Title Lack of Encryption in Object Archive in AxxonSoft Axxon One before 2.0.8
Weaknesses CWE-311
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AxxonSoft

Published:

Updated: 2025-10-08T11:57:58.014Z

Reserved: 2025-09-10T12:38:55.033Z

Link: CVE-2025-10227

cve-icon Vulnrichment

Updated: 2025-09-10T13:09:19.838Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-10T13:15:36.823

Modified: 2025-10-08T12:15:35.903

Link: CVE-2025-10227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-12T09:11:29Z