CVE-2025-10224
10.09.2025, 13:15
Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be denied access or misassigned roles via incorrect evaluation of nested LDAP group memberships during login.Enginsight
| Vendor | Product | Version |
|---|---|---|
| axxonsoft | axxon_one | 𝑥 ≤ 2.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration