nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-10220 CVE-2025-10220
CRITICAL
Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4
Record summary
CVE-2025-10220 has a selected CVSS score of 9.3 (critical).
Description
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages such as Google.Protobuf, DynamicData, System.Runtime.CompilerServices.Unsafe, and others.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AxxonOne C-WerkBrowse AxxonSoft / AxxonOne C-WerkDefault status: unaffected | CVE List | 2.0.0 to ≤ 2.0.4 | affected |
References
2axxonsoft.com
https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories