216.73.216.6

CVE-2025-35061

· Published 09/10/2025 21:15 · Modified 09/10/2025 21:15

Labels: CVE-2025-35061 2025-10-099119a7d8-5eab-497f-8521-727c672e3725CVE-2025-35061CWE-294

Essential information

Published
09/10/2025 21:15
Modified
09/10/2025 21:15
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured NIX service account.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
newforma / newforma info exchange cpe:2.3:a:newforma:newforma_info_exchange:*:*:*:*:*:*:*:*

References