CVE-2025-35054
⚪ Do wiadomości
Przechowywanie klucza szyfrującego w rejestrze Newforma Info Exchange umożliwia dostęp do poświadczeń.
CVSS
5.3
EPSS
0.1%
Exploit
none
Vendor
newforma
Opis źródłowy (NVD)
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2025-10-09 21:15:36 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 13:10:00 UTC |
Referencje
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-282-01.json (9119a7d8-5eab-497f-8521-727c672e3725) [Third Party Advisory]
- https://www.cve.org/CVERecord?id=CVE-2025-35054 (9119a7d8-5eab-497f-8521-727c672e3725) [Third Party Advisory]