Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg8f-f9vp-h6j2

Опубликовано: 09 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 5.3

Описание

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

EPSS

Процентиль: 1%
0.00011
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-257

Связанные уязвимости

CVSS3: 5.3
nvd
4 месяца назад

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

EPSS

Процентиль: 1%
0.00011
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-257