CVE-2025-35057 - Newforma Info Exchange (NIX) forced NTLMv2 authentication via /RemoteWeb/IntegrationServices.ashx
CVE ID : CVE-2025-35057
Published : Oct. 9, 2025, 8:21 p.m. | 11 minutes ago
Description : Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the NIX service account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 9, 2025, 8:21 p.m. | 11 minutes ago
Description : Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the NIX service account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...