{"id":"CVE-2025-10222","title":"Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such…","summary":"Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"axxonsoft","product":"axxon_one","affected":["axxon_one >= 2.0.0, < 2.0.2"],"patched":["axxon_one 2.0.2"],"published":"2025-09-10","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-10222","references":[{"url":"https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories","label":"15ede60e-6fda-426e-be9c-e788f151a377"}],"tags":["nvd"],"epss":0.00121,"epssPercentile":0.01666,"ingestedAt":"2026-09-26T00:22:39.912Z","slug":"CVE-2025-10222","body":"## Overview\n\nExposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool.\n\n## Affected\n\n- `axxon_one >= 2.0.0, < 2.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `axxon_one 2.0.2`","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}