CVE-2025-10223
BaseFortify
Publication date: 2025-09-10
Last updated on: 2025-10-08
Assigner: AxxonSoft
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| axxonsoft | axxon_one | to 2.0.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-613 | According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization." |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Insufficient Session Expiration issue in the Web Admin Panel of AxxonSoft Axxon One versions prior to 2.0.3 on Windows. It allows a local or remote authenticated attacker to continue accessing the system with previously removed privileges by using an unexpired session token until it naturally expires.
How can this vulnerability impact me? :
The vulnerability can allow an attacker who has had their privileges removed to retain access to the system by continuing to use an unexpired session token. This could lead to unauthorized access and potential misuse of the system during the session's lifetime.