CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-35056: project center before 2024.1 (exclusive); +1 more affected products

CVE-2025-35056. CVSS 3.1 base score 5.0 (MEDIUM, NVD). EPSS 0.00354 (percentile 0.26883), scored 2026-10-06.

Affected technology

project center · before 2024.1 (exclusive)
newforma

Project Center · 0 to before 2024.1
Newforma

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically 'NT AUTHORITY\NetworkService', and the ability of StreamStampImage to process the file. Source advisory’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality impact as low; integrity and availability impact as none.

Published

CWE
CWE-22
CCR priority
20.1 /100 (P4)
CVSS 3.1
5.0 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N · NVD
EPSS
0.00354 · percentile 0.26986 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-35056.html