CRITICAL🇵🇱 Wersja polska

CVE-2025-10226

CVSS 9.3v4.0pub. 2025-09-10upd. 2025-12-19

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.

🤖 AI Analysis
How it works

The problem results from Axxon One software's dependency on an outdated PostgreSQL component in the v10.x branch (CWE-1395 — Dependency on Vulnerable Third-Party Component). This version of PostgreSQL contains numerous known vulnerabilities that were fixed only in PostgreSQL 17.4. The database backend is accessible over the network, allowing a remote attacker to directly exploit these vulnerabilities without requiring credentials or user interaction.

Impact

An attacker can obtain privilege escalation, execute arbitrary code (RCE) on the target system, or cause a denial of service (DoS). The vulnerability affects the confidentiality, integrity, and availability of the system.

Mitigation & patch

AxxonSoft Axxon One must be updated to a version containing PostgreSQL 17.4 or newer. Detailed information about available patches should be checked in the vendor references at: https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories. Until the update is applied, it is recommended to restrict network access to the PostgreSQL port only to trusted hosts using a firewall.

Who is affected

AxxonSoft Axxon One (C-Werk) version 2.0.8 and earlier, running on Windows and Linux systems with embedded PostgreSQL v10.x backend.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Axxonsoft Axxon One

    APP
    Axxonsoft
    ≤ 2.0.8
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit