Encryption Bypass in Newforma Info Exchange by Newforma
CVE-2025-35052

6.3MEDIUM

Key Information:

Vendor

Newforma

Vendor
CVE Published:
9 October 2025

What is CVE-2025-35052?

The Newforma Info Exchange (NIX) is affected by a vulnerability that stems from the use of a hard-coded encryption key for certain query parameters. This design flaw enables potential attackers to exploit encrypted parameter values to specify file download paths, effectively bypassing both authentication and authorization measures. The vulnerability primarily concerns the 'qs' parameter utilized in the '/DownloadWeb/download.aspx' endpoint. Although NIX versions 2023.3 and 2024.1 have started to mitigate this issue by limiting the reliance on such hard-coded keys, the shared nature of the key across installations presents an ongoing risk.

Affected Version(s)

Project Center *

Project Center 2024.3

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)
.
CVE-2025-35052 : Encryption Bypass in Newforma Info Exchange by Newforma