Description


Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.

Weaknesses



CWE-532

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.5 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

15ede60e-6fda-426e-be9c-e788f151a377

Vulnerability status

Analyzed

Published

2025-09-10T13:15:35.590

3 months ago

Last modified

2025-12-19T14:24:48.670

5 hours ago