Newforma Info Exchange (NIX) Limited File Read Vulnerability

Vulnerability

A file read vulnerability has been identified in Newforma Info Exchange (NIX) versions prior to 2024.1. The issue arises in the 'StreamStampImage' function of the '/UserWeb/Common/MarkupServices.ashx' endpoint, which accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can exploit this vulnerability to read arbitrary files, depending on the privileges of the NIX application, typically 'NT AUTHORITY\NetworkService', and the capability of 'StreamStampImage' to process the file. The encrypted file path can be generated using a shared, hard-coded secret key, as mentioned in CVE-2025-35052. This vulnerability cannot be exploited by anonymous users, as detailed in CVE-2025-35062.

Impact

Exploitation of this vulnerability allows authenticated attackers to read arbitrary files on the server, potentially leading to the disclosure of sensitive information.

Remediation

Users can upgrade to Newforma Info Exchange version 2024.1 or later to address this vulnerability.

Added: Oct 9, 2025, 9:30 PM
Updated: Oct 9, 2025, 9:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
4.8
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.