Executive brief
Dassault Systèmes DELMIA Apriso, a manufacturing operations management platform used to manage global production and supply chains, contains a critical security flaw. An attacker could exploit this vulnerability to inject and execute malicious code on the system. This could lead to a complete takeover of the manufacturing software, potentially disrupting production lines or exposing sensitive operational data.
Technical details
A code injection vulnerability (CWE-94) exists in Dassault Systèmes DELMIA Apriso from Release 2020 through Release 2025. The flaw stems from improper control of code generation, allowing an attacker to execute arbitrary commands on the host system. While the attack vector is network-based, exploitation requires high privileges (PR:H) and involves high complexity (AC:H). Successful exploitation results in a scope change (S:C), granting the attacker significant impact over the confidentiality, integrity, and availability of the environment. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.
Affected products
- Dassault Systèmes DELMIA Apriso Release 2020 through Release 2025
Timeline
- 2025-08-04: disclosed: Initial CVE publication
- 2025-10-28: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-10-28: advisory: Vendor advisory updated