CVE-2025-10220: Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages such as Google.Protobuf, DynamicData, System.Runtime.CompilerServices.Unsafe, and others.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10220?
CVE-2025-10220 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-10220?
To mitigate CVE-2025-10220, update AxxonSoft Axxon One VMS to version 2.0.5 or later, which addresses the vulnerability.
What types of attacks can exploit CVE-2025-10220?
CVE-2025-10220 can be exploited to execute arbitrary code or bypass security features via vulnerable third-party NuGet packages.
Is CVE-2025-10220 present in all versions of AxxonSoft Axxon One VMS?
CVE-2025-10220 affects AxxonSoft Axxon One VMS versions 2.0.0 through 2.0.4.
Can CVE-2025-10220 be exploited remotely?
Yes, CVE-2025-10220 can be exploited by remote attackers, making it particularly concerning for exposed systems.