AxxonSoft Axxon One VMS Unmaintained Third-Party Components Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in AxxonSoft Axxon One VMS versions 2.0.0 through 2.0.4 on Windows, due to the use of unmaintained third-party components in NuGet dependencies. This flaw enables remote attackers to execute arbitrary code or bypass security features by exploiting vulnerable packages such as Google.Protobuf, DynamicData, and System.Runtime.CompilerServices.Unsafe.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.

Remediation

Users are advised to update to Axxon One VMS version 2.0.8 or later, and to ensure that all third-party NuGet packages are updated to their latest compatible versions.

Added: Sep 10, 2025, 1:22 PM
Updated: Sep 10, 2025, 1:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.