Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-35054

Опубликовано: 09 окт. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:newforma:project_center:*:*:*:*:*:*:*:*
Версия до 2024.3 (включая)

EPSS

Процентиль: 1%
0.00011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-257

Связанные уязвимости

CVSS3: 5.3
github
4 месяца назад

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

EPSS

Процентиль: 1%
0.00011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-257