Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-35051

Опубликовано: 09 окт. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. According to the recommended architecture, the vulnerable NPCS endpoint is only accessible on an internal network. To mitigate this vulnerability, restrict network access to NPCS.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:newforma:project_center:2024.3:*:*:*:*:*:*:*

EPSS

Процентиль: 46%
0.00231
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
github
4 месяца назад

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. According to the recommended architecture, the vulnerable NPCS endpoint is only accessible on an internal network. To mitigate this vulnerability, restrict network access to NPCS.

EPSS

Процентиль: 46%
0.00231
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306