CVE-2025-6204
9.5 CISA KEVDassault Systèmes · DELMIA Apriso
A code injection vulnerability in Dassault Systèmes DELMIA Apriso allows an authenticated attacker with high privileges to execute arbitrary code on the host server.
Executive summary
This critical code injection vulnerability in Dassault Systèmes DELMIA Apriso is currently being exploited in the wild, posing a severe risk of unauthorized remote code execution.
Vulnerability
This is an Improper Control of Generation of Code (CWE-94) flaw. It permits an authenticated attacker with high privileges to inject and execute arbitrary code, potentially leading to total system compromise when chained with other vulnerabilities like CVE-2025-6205.
Business impact
With a CVSS score of 9.5, this vulnerability represents an extreme threat to manufacturing environments utilizing DELMIA Apriso. Successful exploitation grants attackers the ability to execute arbitrary code, which can result in full server compromise, theft of intellectual property, or the disruption of critical production processes. The active exploitation of this flaw significantly increases the likelihood of a high-impact security incident.
Remediation
Immediate Action: Apply the security patches released by Dassault Systèmes in early August 2025 immediately to all affected instances.
Proactive Monitoring: Review system logs for suspicious process execution, unauthorized changes to application configuration files, or anomalous service behavior that may indicate post-exploitation activity.
Compensating Controls: Ensure that access to the DELMIA Apriso management interface is restricted to authorized personnel only, and utilize Web Application Firewalls to inspect and block malicious payloads directed at the application.
Exploitation status
Public Exploit Available: Yes, as documented by the inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog.
Analyst recommendation
The critical nature of this vulnerability, combined with its status in the CISA Known Exploited Vulnerabilities catalog, necessitates an immediate response. IT and security teams must treat this as a high-priority incident and deploy the vendor-provided patches without delay to prevent unauthorized code execution and potential production downtime.