CVE-2025-5086
9.5 CISA KEVDassault Systèmes · DELMIA Apriso
A deserialization of untrusted data vulnerability in Dassault Systèmes DELMIA Apriso allows unauthenticated remote attackers to execute arbitrary code.
Executive summary
This critical deserialization vulnerability in DELMIA Apriso is currently being exploited in the wild, posing an immediate risk of full system compromise.
Vulnerability
This is a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated remote attacker to execute arbitrary code on the host server. The attack involves sending a crafted HTTP request containing a Base64 encoded payload, which is subsequently decompressed and executed by the application.
Business impact
With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational security. Successful exploitation could lead to total system compromise, including the loss of data confidentiality and integrity. Furthermore, because DELMIA Apriso is often integrated into manufacturing environments, an attacker could leverage this access to pivot into sensitive operational technology (OT) networks, resulting in significant production downtime and severe reputational damage.
Remediation
Immediate Action: Apply the security updates provided by Dassault Systèmes immediately via their official customer support and advisory portal.
Proactive Monitoring: Monitor network traffic for anomalous HTTP requests containing suspicious Base64 encoded strings or unexpected GZIP compressed data payloads directed at DELMIA Apriso endpoints.
Compensating Controls: Implement Web Application Firewall (WAF) rules to inspect and block inbound HTTP requests that exhibit patterns associated with serialized object injection or unexpected binary payloads.
Exploitation status
Public Exploit Available: Yes, as the SANS Internet Storm Center has documented active exploitation attempts involving specific malicious payload structures.
Analyst recommendation
Given the confirmed active exploitation and the critical nature of this vulnerability, organizations must treat patching as an urgent priority. Administrators should verify their current version against the affected list and apply the vendor provided security updates without delay. If immediate patching is not possible, prioritize isolating affected instances from the internet to prevent unauthorized access while remediation efforts are finalized.
More Dassault Systèmes CVEs
Sources
Originally found and disclosed by Hacktron AI, per the CVE Program record.