Junglewise Threat Intelligence

CVE-2025-6205: Dassault Systèmes DELMIA Apriso missing authorization

CVE-2025-6205 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2025-10-28

Technologies: Dassault Systèmes DELMIA Apriso. Vendors: Dassault SystèMes, Dassault Systèmes.

Executive brief

Dassault Systèmes DELMIA Apriso, a manufacturing operations management software used to manage global production processes, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass security checks and gain high-level administrative access to the application over the network. This could lead to the theft of sensitive manufacturing data, disruption of production lines, or unauthorized changes to operational workflows. This issue is reportedly being exploited in the wild.

Technical details

A missing authorization vulnerability (CWE-862) exists in Dassault Systèmes DELMIA Apriso from Release 2020 through Release 2025. The flaw allows a remote, unauthenticated attacker to bypass authorization mechanisms due to insufficient validation of user permissions. By exploiting this, an attacker can gain privileged access to the application's administrative functions and sensitive data. The vulnerability has a CVSS score of 9.1 and is confirmed by CISA to be under active exploitation. Users are advised to apply vendor-provided mitigations or patches immediately.

Affected products

  • Dassault Systèmes DELMIA Apriso Release 2020 through Release 2025

Timeline

  • 2025-08-04: disclosed: Initial CVE publication
  • 2025-10-28: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-10-28: advisory: Vendor advisory updated

Related threats