ZeroHour

CVE-2025-5086

KEV PoC moderate

Deserialization of Untrusted Data RCE in Dassault Systèmes DELMIA Apriso

CISA: Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.0 critical
EPSS
92%p100
Published
()
KEV added
AI analysis

CVE-2025-5086 is a deserialization of untrusted data flaw (CWE-502) in Dassault Systèmes DELMIA Apriso that can be reached over the network without privileges or user interaction, though with high attack complexity (CVSS 3.1 score 9.0). By feeding crafted serialized data to the application, an attacker can achieve remote code execution on the affected system, with high impact to confidentiality, integrity, and availability across scope. Any organization running DELMIA Apriso from Release 2020 through Release 2025 is in scope, including manufacturing execution deployments that expose the software to untrusted traffic. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-11, and SANS ISC has reported observed exploit attempts; the EPSS probability of exploitation within 30 days is 91.9%.

What to do: Identify all DELMIA Apriso Release 2020 through Release 2025 deployments in your environment and upgrade to the patched releases specified in the Dassault Systèmes security advisory, as required by CISA KEV/BOD 22-01 guidance. Check whether any Apriso instances are internet-facing or reachable from untrusted networks, since SANS has observed active exploit attempts. If patching is not immediately possible, apply mitigations per vendor instructions or discontinue use of the product, and prioritize it given the 9.0 CVSS score and active exploitation.

Affected
Dassault Systèmes (3DS) DELMIA AprisoRelease 2020 through Release 2025
Estimated exposure
moderatelikely thousands of deployments worldwide (roughly 1k–10k systems), with the internet-exposed subset smaller since MES servers are often internal — DELMIA Apriso is a niche enterprise manufacturing execution system deployed per manufacturing site at large industrial companies rather than mass-market software, so no public install counts exist and this is an order-of-magnitude estimate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

CISA Known Exploited Vulnerability
Affected
Dassault Systèmes DELMIA Apriso
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
3ds
Products
delmia apriso
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news