---
id: CVE-2025-35054
title: >-
  Newforma Info Exchange (NIX) stores credentials  used to configure NPCS in
  'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'
summary: >-
  Newforma Info Exchange (NIX) stores credentials  used to configure NPCS in
  'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials
  are encrypted but the encryption key is stored in the same registry location.
  Authenti…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-257
  - CWE-522
  - CWE-922
vendor: newforma
product: project_center
affected:
  - project_center <= 2024.3
published: '2025-10-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-35054'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-282-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-35054'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.0008
epssPercentile: 0.00142
ingestedAt: '2026-10-08T13:42:55.060Z'
---

## Overview

Newforma Info Exchange (NIX) stores credentials  used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the credentials and the encryption key. If these are Active Directory credentials, an attacker may be able to gain access to additional systems and resources.

## Affected

- `project_center <= 2024.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
