Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Fixes

Solution

Upgrade to Axxon One 2.0.8 or later, where AES-256 encryption of object archive is implemented.


Workaround

No workaround given by the vendor.

History

Wed, 10 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Title Lack of Encryption in Object Archive in AxxonSoft Axxon One before 2.0.8
Weaknesses CWE-311
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AxxonSoft

Published:

Updated: 2025-09-10T13:09:31.093Z

Reserved: 2025-09-10T12:38:55.033Z

Link: CVE-2025-10227

cve-icon Vulnrichment

Updated: 2025-09-10T13:09:19.838Z

cve-icon NVD

Status : Received

Published: 2025-09-10T13:15:36.823

Modified: 2025-09-10T13:15:36.823

Link: CVE-2025-10227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.