CVE-2025-10221
Severity CVSS v4.0:
MEDIUM
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
10/09/2025
Last modified:
11/09/2025
Description
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.
Impact
Base Score 4.0
6.70
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM