CVE-2025-6205
KEVmoderateMissing Authorization in Dassault Systèmes DELMIA Apriso Grants Privileged Access
CISA: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
CVE-2025-6205 is a missing authorization flaw (CWE-862) in Dassault Systèmes DELMIA Apriso, an enterprise manufacturing execution system (MES), affecting all releases from Release 2020 through Release 2025. Because required authorization checks are absent, a remote attacker can reach affected application functionality without any credentials or user interaction, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation allows the attacker to gain privileged access to the application, with high impact on confidentiality and integrity, earning a critical CVSS 3.1 score of 9.1. Any organization running DELMIA Apriso Release 2020 through Release 2025 is affected, typically manufacturers using Apriso to run plant-floor and production operations. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-10-28 amid reports of active exploitation, and EPSS assigns a 72.2% probability of exploitation within 30 days, though no public proof-of-concept is known.
What to do: Apply the mitigations or updates specified in Dassault Systèmes' security advisory for all DELMIA Apriso deployments from Release 2020 through Release 2025, as required by CISA's KEV listing (federal agencies must follow BOD 22-01 timelines or discontinue use). Until patched, restrict network access to Apriso application servers and monitor for unauthenticated or unexpected privileged access to the application. Check vendor release notes for the exact fixed release applicable to your installed Apriso release, since the data here does not specify one.
| Dassault Systèmes DELMIA Apriso | Release 2020 through Release 2025 (per CISA; apply fixes per the vendor's security advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
- Affected
- Dassault Systèmes DELMIA Apriso
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- 3ds
- Products
- delmia apriso
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N