PT-2025-37046 · Axxonsoft · Axxonone

Published

2025-09-10

·

Updated

2025-12-19

·

CVE-2025-10227

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: AxxonSoft Axxon One versions prior to 2.0.8
Description: The Object Archive component in AxxonSoft Axxon One lacks encryption of sensitive data at rest. This allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext.
Recommendations: Update AxxonSoft Axxon One to version 2.0.8 or later.

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2025-10227

Affected Products

Axxonone