Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Newforma project Center
|
|
| CPEs | cpe:2.3:a:newforma:project_center:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Newforma project Center
|
Wed, 15 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Newforma
Newforma project Center Server |
|
| Vendors & Products |
Newforma
Newforma project Center Server |
Thu, 09 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shared across NIX installations. NIX 2023.3 and 2024.1 limit the use of hard-coded keys. | |
| Title | Newforma Info Exchange (NIX) shared hard-coded secret key | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-10-15T16:15:19.858Z
Reserved: 2025-04-15T20:56:24.405Z
Link: CVE-2025-35052
Updated: 2025-10-10T19:36:56.640Z
Status : Analyzed
Published: 2025-10-09T21:15:36.040
Modified: 2025-10-22T15:56:25.910
Link: CVE-2025-35052
No data.
OpenCVE Enrichment
Updated: 2025-10-10T11:17:42Z