Newforma
Newforma Project Center: vulnerabilidades y CVE
Newforma Project Center tiene 14 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses13
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-35062 | Media (6.9) | 0.37% | — | 9 oct 2025 | Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication. |
| CVE-2025-35061 | Alta (8.2) | 0.38% | — | 9 oct 2025 | Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture… |
| CVE-2025-35060 | Media (5.1) | 0.21% | — | 9 oct 2025 | Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web… |
| CVE-2025-35059 | Media (5.3) | 0.21% | — | 9 oct 2025 | Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter. |
| CVE-2025-35057 | Media (6) | 0.33% | — | 9 oct 2025 | Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2… |
| CVE-2025-35056 | Media (5.3) | 0.35% | — | 9 oct 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject… |
| CVE-2025-35055 | Alta (8.7) | 0.54% | — | 9 oct 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can upload and run a web shell… |
| CVE-2025-35054 | Media (4.8) | 0.08% | — | 9 oct 2025 | Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry… |
| CVE-2025-35053 | Media (6.1) | 0.41% | — | 9 oct 2025 | Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT… |
| CVE-2025-35052 | Media (6.3) | 0.37% | — | 9 oct 2025 | Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for… |
| CVE-2025-35051 | Crítica (9.2) | 0.84% | — | 9 oct 2025 | Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT… |
| CVE-2025-35050 | Crítica (9.3) | 0.92% | — | 9 oct 2025 | Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges.… |
| CVE-2025-35058 | Alta (8.2) | 0.38% | — | 9 oct 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2… |
| CVE-2024-32499 | Crítica (9.8) | 0.48% | — | 28 abr 2025 | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.