SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-35054

If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

MEDIUM 4.8EPSS 0.08%

Does this matter?

Lower severity and a low EPSS score (0.08%). Track it; it rarely justifies an emergency change on its own.

Description

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

CVSS 4.0
4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.08% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-257, CWE-522, CWE-922
Affected
newforma/project center
Source
9119a7d8-5eab-497f-8521-727c672e3725

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.