nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-10222 CVE-2025-10222
MEDIUM
Sensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMS
Record summary
CVE-2025-10222 has a selected CVSS score of 4.8 (medium).
Description
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AxxonOne C-WerkBrowse AxxonSoft / AxxonOne C-WerkDefault status: unaffected | CVE List | 2.0.0 to ≤ 2.0.1 | affected |
References
2axxonsoft.com
https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories