CVE-2025-10227

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon OneĀ (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-10 13:15

Updated : 2025-12-19 13:48


NVD link : CVE-2025-10227

Mitre link : CVE-2025-10227

CVE.ORG link : CVE-2025-10227


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

axxonsoft

  • axxon_one
CWE
CWE-311

Missing Encryption of Sensitive Data