CVE-2025-10220
BaseFortify
Publication date: 2025-09-10
Last updated on: 2025-12-19
Assigner: AxxonSoft
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| axxonsoft | axxon_one | From 2.0.0 (inc) to 2.0.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1104 | The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the use of unmaintained third-party components in the NuGet dependencies of AxxonSoft Axxon One VMS versions 2.0.0 through 2.0.4 on Windows. An attacker can exploit vulnerabilities in these outdated packages, such as Google.Protobuf, DynamicData, and System.Runtime.CompilerServices.Unsafe, to execute arbitrary code or bypass security features remotely.
How can this vulnerability impact me? :
The vulnerability can allow a remote attacker to execute arbitrary code on the affected system or bypass security features, potentially leading to full system compromise, data theft, or disruption of services.