5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.
Basic Information
ID
CVE-2025-10223
Source
AxxonSoft
Published
Sep 10, 2025 at 12:35
Modified
Sep 10, 2025 at 13:24
Affected Product
Vendor
AxxonSoft
Product
AxxonOne
Affected Versions
AxxonSoft AxxonOne 0