Executive brief
Dassault Systèmes DELMIA Apriso, a manufacturing operations management platform used to manage global production and supply chains, contains a critical security flaw. An attacker can exploit this vulnerability to take full control of the server remotely without needing any login credentials. This could lead to significant operational disruptions, theft of sensitive manufacturing data, or a complete shutdown of production facilities.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in Dassault Systèmes DELMIA Apriso from Release 2020 through Release 2025. The flaw allows an unauthenticated remote attacker to execute arbitrary code on the host system by sending specially crafted serialized objects over the network. While the attack complexity is rated as high, the vulnerability has been observed being exploited in the wild. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability, with the impact extending beyond the immediate component (Scope: Changed). Users are advised to apply vendor-provided mitigations or patches immediately.
Affected products
- Dassault Systèmes DELMIA Apriso Release 2020 through Release 2025
Timeline
- 2025-06-02: disclosed: Initial disclosure by Dassault Systèmes
- 2025-09-11: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-09-11: exploited: Confirmed active exploitation in the wild