{"api_version":"v1","generated_at":"2026-10-09T13:20:00+00:00","product":{"cve_count":7,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-axxonsoft-axxonone-c-werk-4a24a95df743","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"AxxonOne C-Werk","next_cursor":null,"observations":[{"affected":"AxxonOne C-Werk: \u2264 2.0.8","affected_versions_present":true,"cve_id":"CVE-2025-10227","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10227","fixed":"Upgrade to Axxon One (C-Werk) 2.0.8 or later, where AES-256 encryption of object archive is implemented.","last_modified":"2025-10-08T11:57:58.014Z","patch_url":"https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories","primary_source":"","published":"2025-09-10T12:39:12.391Z"},{"affected":"\u2264 2.0.8","affected_versions_present":true,"cve_id":"CVE-2025-10226","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10226","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-08T11:56:42.741Z","patch_url":"","primary_source":"","published":"2025-09-10T12:38:42.549Z"},{"affected":"AxxonOne C-Werk: \u2264 2.0.6","affected_versions_present":true,"cve_id":"CVE-2025-10225","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10225","fixed":"Upgrade to Axxon One (C-Werk) with OpenSSL 3.0.13 or later, where session key management logic was refactored to avoid unsafe memory reallocations.","last_modified":"2025-10-08T11:51:39.395Z","patch_url":"https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories","primary_source":"","published":"2025-09-10T12:37:15.117Z"},{"affected":"\u2264 2.0.2","affected_versions_present":true,"cve_id":"CVE-2025-10224","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10224","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-08T11:50:36.640Z","patch_url":"","primary_source":"","published":"2025-09-10T12:36:22.954Z"},{"affected":"AxxonOne C-Werk: \u2264 2.0.3","affected_versions_present":true,"cve_id":"CVE-2025-10223","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10223","fixed":"Upgrade to 2.0.3 or later, where Web UI enforces forced logout when role changes occur.","last_modified":"2025-10-08T11:49:37.530Z","patch_url":"https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories","primary_source":"","published":"2025-09-10T12:35:32.800Z"},{"affected":"AxxonOne C-Werk: 2.0.0 \u2264 2.0.1","affected_versions_present":true,"cve_id":"CVE-2025-10222","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10222","fixed":"Upgrade to Axxon One 2.0.2 (C-Werk) or later, where the diagnostic export tool has been refactored to exclude licensing-related sensitive variables.","last_modified":"2025-10-08T11:46:46.982Z","patch_url":"https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories","primary_source":"","published":"2025-09-10T12:34:50.665Z"},{"affected":"AxxonOne C-Werk: 2.0.0 \u2264 2.0.4","affected_versions_present":true,"cve_id":"CVE-2025-10220","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10220","fixed":"Update to Axxon One VMS 2.0.5 or later, where vulnerable NuGet dependencies have been upgraded to secure versions (e.g., Google.Protobuf 3.31.0, DynamicData 9.3.2, System.Runtime.CompilerServices.Unsafe 6.1.2).","last_modified":"2025-10-08T11:26:39.629Z","patch_url":"https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories","primary_source":"","published":"2025-09-10T12:28:39.023Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"AxxonSoft"}}
