CVE-2025-5086
KEV PoC moderateDeserialization of Untrusted Data RCE in Dassault Systèmes DELMIA Apriso
CISA: Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability
CVE-2025-5086 is a deserialization of untrusted data flaw (CWE-502) in Dassault Systèmes DELMIA Apriso that can be reached over the network without privileges or user interaction, though with high attack complexity (CVSS 3.1 score 9.0). By feeding crafted serialized data to the application, an attacker can achieve remote code execution on the affected system, with high impact to confidentiality, integrity, and availability across scope. Any organization running DELMIA Apriso from Release 2020 through Release 2025 is in scope, including manufacturing execution deployments that expose the software to untrusted traffic. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-11, and SANS ISC has reported observed exploit attempts; the EPSS probability of exploitation within 30 days is 91.9%.
What to do: Identify all DELMIA Apriso Release 2020 through Release 2025 deployments in your environment and upgrade to the patched releases specified in the Dassault Systèmes security advisory, as required by CISA KEV/BOD 22-01 guidance. Check whether any Apriso instances are internet-facing or reachable from untrusted networks, since SANS has observed active exploit attempts. If patching is not immediately possible, apply mitigations per vendor instructions or discontinue use of the product, and prioritize it given the 9.0 CVSS score and active exploitation.
| Dassault Systèmes (3DS) DELMIA Apriso | Release 2020 through Release 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
- Affected
- Dassault Systèmes DELMIA Apriso
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- 3ds
- Products
- delmia apriso
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H