CVE-2025-35054

⚪ Do wiadomości

Przechowywanie klucza szyfrującego w rejestrze Newforma Info Exchange umożliwia dostęp do poświadczeń.

CVSS
5.3
EPSS
0.1%
Exploit
none
Vendor
newforma
Opis źródłowy (NVD)

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2025-10-09 21:15:36 UTC
Ostatnia modyfikacja (NVD)2026-10-08 13:10:00 UTC
Referencje