CVE-2025-10222: Sensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMS
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10222?
CVE-2025-10222 has been classified as a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2025-10222?
To address CVE-2025-10222, update AxxonSoft Axxon One VMS to a version later than 2.0.1.
What type of information is exposed in CVE-2025-10222?
CVE-2025-10222 exposes sensitive licensing-related information, including timestamps and license states.
Who is affected by CVE-2025-10222?
CVE-2025-10222 affects users of AxxonSoft Axxon One VMS versions 2.0.0 and 2.0.1 on Windows.
Can a remote attacker exploit CVE-2025-10222?
No, CVE-2025-10222 can only be exploited by local attackers.