CVE-2025-6204

9.5 CISA KEV

Dassault Systèmes · DELMIA Apriso

A code injection vulnerability in Dassault Systèmes DELMIA Apriso allows an authenticated attacker with high privileges to execute arbitrary code on the host server.

Executive summary

This critical code injection vulnerability in Dassault Systèmes DELMIA Apriso is currently being exploited in the wild, posing a severe risk of unauthorized remote code execution.

Vulnerability

This is an Improper Control of Generation of Code (CWE-94) flaw. It permits an authenticated attacker with high privileges to inject and execute arbitrary code, potentially leading to total system compromise when chained with other vulnerabilities like CVE-2025-6205.

Business impact

With a CVSS score of 9.5, this vulnerability represents an extreme threat to manufacturing environments utilizing DELMIA Apriso. Successful exploitation grants attackers the ability to execute arbitrary code, which can result in full server compromise, theft of intellectual property, or the disruption of critical production processes. The active exploitation of this flaw significantly increases the likelihood of a high-impact security incident.

Remediation

Immediate Action: Apply the security patches released by Dassault Systèmes in early August 2025 immediately to all affected instances.

Proactive Monitoring: Review system logs for suspicious process execution, unauthorized changes to application configuration files, or anomalous service behavior that may indicate post-exploitation activity.

Compensating Controls: Ensure that access to the DELMIA Apriso management interface is restricted to authorized personnel only, and utilize Web Application Firewalls to inspect and block malicious payloads directed at the application.

Exploitation status

Public Exploit Available: Yes, as documented by the inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog.

Analyst recommendation

The critical nature of this vulnerability, combined with its status in the CISA Known Exploited Vulnerabilities catalog, necessitates an immediate response. IT and security teams must treat this as a high-priority incident and deploy the vendor-provided patches without delay to prevent unauthorized code execution and potential production downtime.

More Dassault Systèmes CVEs

Sources