Vulnerability Description
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages such as Google.Protobuf, DynamicData, System.Runtime.CompilerServices.Unsafe, and others.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Axxonsoft | Axxon One | >= 2.0.0, <= 2.0.4 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-10220?
CVE-2025-10220 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or...
How severe is CVE-2025-10220?
CVE-2025-10220 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-10220?
Check the references section above for vendor advisories and patch information. Affected products include: Axxonsoft Axxon One.