Newforma Info Exchange Remote Service Vulnerability
CVE-2025-35057

6MEDIUM

Key Information:

Vendor

Newforma

Vendor
CVE Published:
9 October 2025

What is CVE-2025-35057?

The Newforma Info Exchange (NIX) platform has a vulnerability that permits a remote, unauthenticated attacker to initiate an SMB connection to a system under their control. Through this exploit, the attacker has the capability to capture the NTLMv2 hash associated with the NIX service account, posing a significant risk to user credentials and system security.

Affected Version(s)

Project Center 0 < 2024.3

Project Center 2024.3

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)
.
CVE-2025-35057 : Newforma Info Exchange Remote Service Vulnerability