CVE-2025-10225

HIGH

AxxonSoft Axxon One < 2.0.6 - Denial of Service via OpenSSL Session Key Reallocation

Title source: llm
STIX 2.1

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.

Scores

CVSS v3 7.5
EPSS 0.0037
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119
Status published
Products (1)
axxonsoft/axxon_one < 2.0.6
Published Sep 10, 2025
Tracked Since Feb 18, 2026