Vulnerability Description
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Axxonsoft | Axxon One | >= 2.0.0, < 2.0.2 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-10222?
CVE-2025-10222 is a vulnerability with a CVSS score of 3.3 (LOW). Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obta...
How severe is CVE-2025-10222?
CVE-2025-10222 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10222?
Check the references section above for vendor advisories and patch information. Affected products include: Axxonsoft Axxon One.