Encryption Bypass in Newforma Info Exchange by Newforma
CVE-2025-35052
What is CVE-2025-35052?
The Newforma Info Exchange (NIX) is affected by a vulnerability that stems from the use of a hard-coded encryption key for certain query parameters. This design flaw enables potential attackers to exploit encrypted parameter values to specify file download paths, effectively bypassing both authentication and authorization measures. The vulnerability primarily concerns the 'qs' parameter utilized in the '/DownloadWeb/download.aspx' endpoint. Although NIX versions 2023.3 and 2024.1 have started to mitigate this issue by limiting the reliance on such hard-coded keys, the shared nature of the key across installations presents an ongoing risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Project Center *
Project Center 2024.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
