CVE ID: CVE-2025-35062 Published Date: 2025-10-09 Updated Date: 2025-10-09 Title: Newforma Info Exchange (NIX) Default Anonymous Access Description: Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication. CWE: CWE-276: Incorrect Default Permissions CVSS Scores: - Version 4.0: Score 6.9, Severity MEDIUM, Vector String CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VL:N/VA:N/SC:N - Version 3.1: Score 5.3, Severity MEDIUM, Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Product Status: - Vendor: Newforma - Product: Project Center - Versions Affected: from n before 2023.1 Credits: Shadron Gudmunson, Luke Rindels, Robert McCain, Asjha Stus, Adam Merrill, Ryan Kao, Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT) References: - raw.githubusercontent.com: url - cve.org: url