Newforma Info Exchange Remote Service Vulnerability
CVE-2025-35057
6MEDIUM
What is CVE-2025-35057?
The Newforma Info Exchange (NIX) platform has a vulnerability that permits a remote, unauthenticated attacker to initiate an SMB connection to a system under their control. Through this exploit, the attacker has the capability to capture the NTLMv2 hash associated with the NIX service account, posing a significant risk to user credentials and system security.
Affected Version(s)
Project Center 0 < 2024.3
Project Center 2024.3
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)