Unauthenticated Remote Code Execution in Newforma Info Exchange by Newforma
CVE-2025-35061
8.2HIGH
What is CVE-2025-35061?
The vulnerability present in Newforma Info Exchange (NIX) allows an unauthenticated remote attacker to initiate an SMB connection to a malicious server. This exploitation can lead to the leakage of the NTLMv2 hash for the service account configured within the NIX system, potentially enabling unauthorized access and control over the affected services. Organizations using NIX should review their configurations and apply the latest security patches to mitigate this risk.
Affected Version(s)
Project Center 0 < 2023.2
Project Center 2023.2
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)