216.73.216.36

CVE-2025-10222

· Published 10/09/2025 13:15 · Modified 10/09/2025 13:15

Labels: CVE-2025-10222 15ede60e-6fda-426e-be9c-e788f151a3772025-09-10CVE-2025-10222CWE-200

Essential information

Published
10/09/2025 13:15
Modified
10/09/2025 13:15
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
15ede60e-6fda-426e-be9c-e788f151a377
NVD
View on NVD

Affected products (CPE)

ProductCPE
axxonsoft / axxon one vms cpe:2.3:a:axxonsoft:axxon_one_vms:2.0.0-2.0.1:*:*:*:*:*:*:*

References