Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
History

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Axxonsoft
Axxonsoft axxon One
Linux
Linux linux
Microsoft
Microsoft windows
Vendors & Products Axxonsoft
Axxonsoft axxon One
Linux
Linux linux
Microsoft
Microsoft windows

Wed, 10 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Title Lack of Encryption in Object Archive in AxxonSoft Axxon One before 2.0.8
Weaknesses CWE-311
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AxxonSoft

Published: 2025-09-10T12:39:12.391Z

Updated: 2025-09-10T13:09:31.093Z

Reserved: 2025-09-10T12:38:55.033Z

Link: CVE-2025-10227

cve-icon Vulnrichment

Updated: 2025-09-10T13:09:19.838Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-10T13:15:36.823

Modified: 2025-09-11T17:14:10.147

Link: CVE-2025-10227

cve-icon Redhat

No data.