CRITICAL🇵🇱 Wersja polska

CVE-2025-10220

CVSS 9.3v4.0pub. 2025-09-10upd. 2025-12-19

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages such as Google.Protobuf, DynamicData, System.Runtime.CompilerServices.Unsafe, and others.

🤖 AI Analysis
How it works

Axxon One VMS system in versions 2.0.0–2.0.4 uses outdated and unpatched NuGet packages, such as Google.Protobuf, DynamicData, System.Runtime.CompilerServices.Unsafe and others. An attacker can exploit known vulnerabilities in these libraries by sending appropriately crafted network requests. Since the attack does not require authentication or user interaction, the attack surface is very broad.

Impact

An attacker can remotely execute arbitrary code on the victim's system (RCE) or bypass application security mechanisms, which may lead to complete takeover of the video management system.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Additional information is available in AxxonSoft's vulnerability disclosure policy at: https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories

Who is affected

AxxonSoft Axxon One VMS in versions 2.0.0 to 2.0.4 running on Windows systems

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Axxonsoft Axxon One

    APP
    Axxonsoft
    2.0.0 – 2.0.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-10226CRITICAL9.3PL ✓same product

RCE i privilege escalation w AxxonSoft Axxon One przez podatny komponent PostgreSQL

CVE-2025-10225HIGH8.7same product

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session...

CVE-2025-10223MEDIUM5.3same product

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0....

CVE-2025-10221MEDIUM6.7same product

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One /...

CVE-2025-10227MEDIUM5.1same product

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk)...