CVE-2025-10222
BaseFortify
Publication date: 2025-09-10
Last updated on: 2025-10-08
Assigner: AxxonSoft
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| axxonsoft | axxon_one | From 2.0.0 (inc) to 2.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Exposure of Sensitive Information to an Unauthorized Actor in the diagnostic dump component of AxxonSoft Axxon One VMS versions 2.0.0 through 2.0.1 on Windows. A local attacker can read diagnostic export files created by the built-in troubleshooting tool to obtain licensing-related information such as timestamps, license states, and registry values.
How can this vulnerability impact me? :
The vulnerability allows a local attacker to access sensitive licensing information that should be protected. While it does not directly impact system integrity or availability, unauthorized disclosure of licensing data could potentially aid attackers in further exploitation or unauthorized use of the software.