VYPR

Axxon One VMS

by AxxonSoft

CVEs (3)

  • CVE-2025-10220CriSep 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages…

  • CVE-2025-10224MedSep 10, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be denied access or misassigned roles via incorrect evaluation of nested LDAP group memberships during login.

  • CVE-2025-10222LowSep 10, 2025
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and…