CVE-2025-10227
BaseFortify
Publication date: 2025-09-10
Last updated on: 2025-12-19
Assigner: AxxonSoft
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| axxonsoft | axxon_one | to 2.0.8 (exc) |
| linux | linux_kernel | * |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-311 | The product does not encrypt sensitive or critical information before storage or transmission. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability can impact you by allowing a local attacker with access to exported storage or stolen physical drives to obtain sensitive archive data in plaintext. This could lead to unauthorized disclosure of sensitive information.
Can you explain this vulnerability to me?
This vulnerability is a Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component of AxxonSoft Axxon One versions before 2.0.8 on Windows and Linux. It allows a local attacker who has access to exported storage or stolen physical drives to extract sensitive archive data in plaintext because the data is not encrypted at rest.