« Volver al listado

Newforma

Newforma Project Center: vulnerabilidades y CVE

Newforma Project Center tiene 14 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses13
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-35062Media (6.9)0.37%—9 oct 2025
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.
CVE-2025-35061Alta (8.2)0.38%—9 oct 2025
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture…
CVE-2025-35060Media (5.1)0.21%—9 oct 2025
Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web…
CVE-2025-35059Media (5.3)0.21%—9 oct 2025
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.
CVE-2025-35057Media (6)0.33%—9 oct 2025
Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2…
CVE-2025-35056Media (5.3)0.35%—9 oct 2025
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject…
CVE-2025-35055Alta (8.7)0.54%—9 oct 2025
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can upload and run a web shell…
CVE-2025-35054Media (4.8)0.08%—9 oct 2025
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry…
CVE-2025-35053Media (6.1)0.41%—9 oct 2025
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT…
CVE-2025-35052Media (6.3)0.37%—9 oct 2025
Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for…
CVE-2025-35051Crítica (9.2)0.84%—9 oct 2025
Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT…
CVE-2025-35050Crítica (9.3)0.92%—9 oct 2025
Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges.…
CVE-2025-35058Alta (8.2)0.38%—9 oct 2025
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2…
CVE-2024-32499Crítica (9.8)0.48%—28 abr 2025
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1059 Command and Scripting Interpreter2
  3. T1187 Forced Authentication2
  4. T1210 Exploitation of Remote Services1
  5. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.