ZeroHour

CVE-2025-6205

KEVmoderate

Missing Authorization in Dassault Systèmes DELMIA Apriso Grants Privileged Access

CISA: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

CVSS 3.1
9.1 critical
EPSS
73%p99
Published
()
KEV added
AI analysis

CVE-2025-6205 is a missing authorization flaw (CWE-862) in Dassault Systèmes DELMIA Apriso, an enterprise manufacturing execution system (MES), affecting all releases from Release 2020 through Release 2025. Because required authorization checks are absent, a remote attacker can reach affected application functionality without any credentials or user interaction, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation allows the attacker to gain privileged access to the application, with high impact on confidentiality and integrity, earning a critical CVSS 3.1 score of 9.1. Any organization running DELMIA Apriso Release 2020 through Release 2025 is affected, typically manufacturers using Apriso to run plant-floor and production operations. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-10-28 amid reports of active exploitation, and EPSS assigns a 72.2% probability of exploitation within 30 days, though no public proof-of-concept is known.

What to do: Apply the mitigations or updates specified in Dassault Systèmes' security advisory for all DELMIA Apriso deployments from Release 2020 through Release 2025, as required by CISA's KEV listing (federal agencies must follow BOD 22-01 timelines or discontinue use). Until patched, restrict network access to Apriso application servers and monitor for unauthenticated or unexpected privileged access to the application. Check vendor release notes for the exact fixed release applicable to your installed Apriso release, since the data here does not specify one.

Affected
Dassault Systèmes DELMIA AprisoRelease 2020 through Release 2025 (per CISA; apply fixes per the vendor's security advisory)
Estimated exposure
moderate≈1,000–5,000 plant/site deployments of Apriso instances worldwide (exact count unknown) — DELMIA Apriso is enterprise MES software deployed per manufacturing site at large industrial (e.g., automotive, aerospace, CPG) companies rather than mass-market software; no public install counts or scan data are available, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

CISA Known Exploited Vulnerability
Affected
Dassault Systèmes DELMIA Apriso
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
3ds
Products
delmia apriso
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news