---
id: CVE-2025-10222
title: >-
  Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the
  diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through
  2.0.1 on Windows allows a local attacker to obtain licensing-related
  information such…
summary: >-
  Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the
  diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through
  2.0.1 on Windows allows a local attacker to obtain licensing-related
  information such…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: axxonsoft
product: axxon_one
affected:
  - 'axxon_one >= 2.0.0, < 2.0.2'
patched:
  - axxon_one 2.0.2
published: '2025-09-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10222'
references:
  - url: >-
      https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories
    label: 15ede60e-6fda-426e-be9c-e788f151a377
tags:
  - nvd
epss: 0.00121
epssPercentile: 0.01666
ingestedAt: '2026-09-26T00:22:39.912Z'
---

## Overview

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool.

## Affected

- `axxon_one >= 2.0.0, < 2.0.2`

## Remediation

Upgrade past the affected range:

- `axxon_one 2.0.2`
