Aller au contenu

Fiche vulnérabilité

CVE-2025-10223 : faille élevée axxonsoft axxon one (CVSS 8.1)

Description

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
10 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • axxonsoft axxon one

Références

Rechercher une autre vulnérabilité dans la base CVE