216.73.217.22

CVE-2025-35058

· Published 09/10/2025 21:15 · Modified 09/10/2025 21:15

Labels: CVE-2025-35058 2025-10-099119a7d8-5eab-497f-8521-727c672e3725CVE-2025-35058CWE-294

Essential information

Published
09/10/2025 21:15
Modified
09/10/2025 21:15
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
newforma / info exchange cpe:2.3:a:newforma:info_exchange:*:*:*:*:*:*:*:*

References