Unauthenticated Remote Code Execution in Newforma Info Exchange by Newforma
CVE-2025-35061

8.2HIGH

Key Information:

Vendor

Newforma

Vendor
CVE Published:
9 October 2025

What is CVE-2025-35061?

The vulnerability present in Newforma Info Exchange (NIX) allows an unauthenticated remote attacker to initiate an SMB connection to a malicious server. This exploitation can lead to the leakage of the NTLMv2 hash for the service account configured within the NIX system, potentially enabling unauthorized access and control over the affected services. Organizations using NIX should review their configurations and apply the latest security patches to mitigate this risk.

Affected Version(s)

Project Center 0 < 2023.2

Project Center 2023.2

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)
.
CVE-2025-35061 : Unauthenticated Remote Code Execution in Newforma Info Exchange by Newforma