ZeroHour

CVE-2025-6204

KEVmoderate

Code Injection in Dassault Systèmes DELMIA Apriso Under Active Exploitation

CISA: Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

CVSS 3.1
8.0 high
EPSS
77%p100
Published
()
KEV added
AI analysis

CVE-2025-6204 is an Improper Control of Generation of Code (CWE-94) code injection vulnerability in Dassault Systèmes' DELMIA Apriso manufacturing execution software, affecting Release 2020 through Release 2025. Per the CVSS 3.1 vector (AV:N/AC:H/PR:H/UI:N/S:C), an attacker with network access to the application and high-level privileges can trigger the flaw without user interaction and execute arbitrary code; the changed scope indicates the compromise can extend beyond the vulnerable component, with high impact to confidentiality, integrity and availability. Organizations running the affected releases — typically large manufacturers using Apriso as a MES in production environments — are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-28, confirming it is being actively exploited, and the 77.1% EPSS (100th percentile) indicates a very high likelihood of exploitation in the next 30 days; no public proof-of-concept is known.

What to do: Apply the vendor's fixes or mitigations per Dassault Systèmes' security advisory (this is CISA's required action), following BOD 22-01 guidance if you are a federal agency using Apriso as a cloud service. Inventory all Apriso deployments running Release 2020 through Release 2025, restrict network access to those systems, and review high-privileged accounts for signs of compromise since exploitation requires such privileges. Ransomware association is currently unknown, so treat active exploitation as confirmed and prioritize patching.

Affected
Dassault Systèmes (3DS) DELMIA AprisoRelease 2020 through Release 2025 (inclusive)
Estimated exposure
moderateapproximately 1,000-10,000 manufacturing-plant/site deployments worldwide (estimate) — No public install counts or internet-exposure scans exist for this enterprise MES, so the estimate is based on deployment patterns: Apriso is licensed per manufacturing plant/site to large industrial firms, implying on the order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Dassault Systèmes DELMIA Apriso
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
3ds
Products
delmia apriso
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news