← CVE Tracker
7.5HIGH

CVE-2025-10225 — Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based…

Axxonsoft · Axxon One · Published 10 Sept 2025 · Modified 26 Sept 2026

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggering memory reallocation errors when handling expired session keys.

References

What to do
  1. Check whether Axxon One is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-10225