AxxonSoft Axxon One VMS Unmaintained Third-Party Components Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A vulnerability exists in AxxonSoft Axxon One VMS versions 2.0.0 through 2.0.4 on Windows, due to the use of unmaintained third-party components in NuGet dependencies. This flaw enables remote attackers to execute arbitrary code or bypass security features by exploiting vulnerable packages such as Google.Protobuf, DynamicData, and System.Runtime.CompilerServices.Unsafe.
Impact
Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.
Remediation
Users are advised to update to Axxon One VMS version 2.0.8 or later, and to ensure that all third-party NuGet packages are updated to their latest compatible versions.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
