Anonymous Authentication Vulnerability in Newforma Info Exchange Software
CVE-2025-35062

6.9MEDIUM

Key Information:

Vendor

Newforma

Vendor
CVE Published:
9 October 2025

What is CVE-2025-35062?

Newforma Info Exchange (NIX) prior to version 2023.1 allows anonymous authentication by default, posing a security risk. This vulnerability enables unauthenticated attackers to exploit further vulnerabilities that typically require user authentication. Organizations using affected NIX versions are urged to update their software to mitigate potential attacks.

Affected Version(s)

Project Center 0 < 2023.1

Project Center 2023.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)
.
CVE-2025-35062 : Anonymous Authentication Vulnerability in Newforma Info Exchange Software