PT-2025-41470 · Newforma · Newforma Info Exchange

Adam Merrill

+6

·

Published

2025-10-09

·

Updated

2025-10-09

·

CVE-2025-35054

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Newforma Info Exchange (NIX) (affected versions not specified)
Description Newforma Info Exchange (NIX) stores credentials used to configure NPCS in the registry location 'HKLMSoftwareWOW6432NodeNewformaversionCredentials'. These credentials are encrypted, but the encryption key is also stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-35054

Affected Products

Newforma Info Exchange