CVE-2025-10224 describes an Improper Authentication vulnerability (CWE-287) in AxxonSoft Axxon One (C-Werk) version 2.0.2 and earlier, specifically within its LDAP authentication engine on Windows. This flaw allows a remote authenticated user to be incorrectly denied access or assigned the wrong roles due to faulty evaluation of nested LDAP group memberships during login. The vulnerability carries a CVSS score of 7.1 (HIGH), indicating it can be exploited over the network with low complexity by a low-privileged user, potentially leading to a high impact on availability and low impact on integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has also received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.2CPE matchmatch criteria | cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.