Description


Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest.

Weaknesses



CWE-311

CVSS impact metrics


CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

4.6 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

15ede60e-6fda-426e-be9c-e788f151a377

Vulnerability status

Analyzed

Published

2025-09-10T13:15:36.823

3 months ago

Last modified

2025-12-19T13:48:18.410

5 hours ago