Description
Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.
References
CVSS impact metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.6 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
15ede60e-6fda-426e-be9c-e788f151a377
Vulnerability status
Analyzed
Published
2025-09-10T13:15:36.823
3 months agoLast modified
2025-12-19T13:48:18.410
5 hours ago