Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-35058


Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account.


Published

2025-10-09T21:15:36.983

Last Modified

2025-10-22T16:51:24.840

Status

Analyzed

Source

9119a7d8-5eab-497f-8521-727c672e3725

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-294

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application newforma project_center < 2023.2 Yes

References