nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-10225 CVE-2025-10225
HIGH
Incorrect Memory Allocation in OpenSSL-Based Session Module in AxxonSoft Axxon One (C-Werk)
Record summary
CVE-2025-10225 has a selected CVSS score of 8.7 (high).
Description
Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AxxonOne C-WerkBrowse AxxonSoft / AxxonOne C-WerkDefault status: unaffected | CVE List | Through 2.0.6 | affected |
References
2axxonsoft.com
https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories