CVE-2025-6204
KEVmoderateCode Injection in Dassault Systèmes DELMIA Apriso Under Active Exploitation
CISA: Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
CVE-2025-6204 is an Improper Control of Generation of Code (CWE-94) code injection vulnerability in Dassault Systèmes' DELMIA Apriso manufacturing execution software, affecting Release 2020 through Release 2025. Per the CVSS 3.1 vector (AV:N/AC:H/PR:H/UI:N/S:C), an attacker with network access to the application and high-level privileges can trigger the flaw without user interaction and execute arbitrary code; the changed scope indicates the compromise can extend beyond the vulnerable component, with high impact to confidentiality, integrity and availability. Organizations running the affected releases — typically large manufacturers using Apriso as a MES in production environments — are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-28, confirming it is being actively exploited, and the 77.1% EPSS (100th percentile) indicates a very high likelihood of exploitation in the next 30 days; no public proof-of-concept is known.
What to do: Apply the vendor's fixes or mitigations per Dassault Systèmes' security advisory (this is CISA's required action), following BOD 22-01 guidance if you are a federal agency using Apriso as a cloud service. Inventory all Apriso deployments running Release 2020 through Release 2025, restrict network access to those systems, and review high-privileged accounts for signs of compromise since exploitation requires such privileges. Ransomware association is currently unknown, so treat active exploitation as confirmed and prioritize patching.
| Dassault Systèmes (3DS) DELMIA Apriso | Release 2020 through Release 2025 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.
- Affected
- Dassault Systèmes DELMIA Apriso
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- 3ds
- Products
- delmia apriso
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H