Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24893 | Unauthenticated RCE via Eval Injection in XWiki Platform SolrSearch XWiki Platform contains an eval injection flaw (CWE-95) that allows any unauthenticated guest user to execute arbitrary code on the hosting server. An attacker triggers the flaw by sending a crafted request to the platform's SolrSearch functionality, which evaluates attacker-controlled input without authentication. Successful exploitation yields arbitrary remote code execution with the privileges of the wiki application, potentially enabling full server compromise. Any deployment of XWiki Platform is affected, with internet-exposed wikis at the highest risk; the affected version ranges are not specified in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-30, indicating confirmed in-the-wild exploitation (ransomware use unconfirmed), and EPSS assigns a ~99.9% probability of exploitation within 30 days. Do: Upgrade to a patched XWiki Platform release per the vendor's security advisory (fixed version numbers not provided in the available data); as interim mitigation, restrict untrusted access to the SolrSearch endpoint and review access logs for anomalous search requests and post-exploitation indicators such as unusual application-server child processes, new files, or webshells. The 2025-10-30 KEV listing makes remediation mandatory for U.S. federal agencies under BOD 22-01, and given the unauthenticated RCE with near-certain exploitation probability, internet-exposed wikis should be patched urgently. | 9.8 | 100% | KEV PoC |
| moderate≈1,000–10,000 internet-exposed XWiki instances (total deployments, including intranets, unknown) | |
| CVE-2025-5086 | Deserialization of Untrusted Data RCE in Dassault Systèmes DELMIA Apriso CVE-2025-5086 is a deserialization of untrusted data flaw (CWE-502) in Dassault Systèmes DELMIA Apriso that can be reached over the network without privileges or user interaction, though with high attack complexity (CVSS 3.1 score 9.0). By feeding crafted serialized data to the application, an attacker can achieve remote code execution on the affected system, with high impact to confidentiality, integrity, and availability across scope. Any organization running DELMIA Apriso from Release 2020 through Release 2025 is in scope, including manufacturing execution deployments that expose the software to untrusted traffic. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-11, and SANS ISC has reported observed exploit attempts; the EPSS probability of exploitation within 30 days is 91.9%. Do: Identify all DELMIA Apriso Release 2020 through Release 2025 deployments in your environment and upgrade to the patched releases specified in the Dassault Systèmes security advisory, as required by CISA KEV/BOD 22-01 guidance. Check whether any Apriso instances are internet-facing or reachable from untrusted networks, since SANS has observed active exploit attempts. If patching is not immediately possible, apply mitigations per vendor instructions or discontinue use of the product, and prioritize it given the 9.0 CVSS score and active exploitation. | 9.0 | 92% | KEV PoC |
| moderatelikely thousands of deployments worldwide (roughly 1k–10k systems), with the internet-exposed subset smaller since MES servers are often internal | |
| CVE-2025-6205 +1 in the same advisory: …6204 | Missing Authorization in Dassault Systèmes DELMIA Apriso Grants Privileged Access CVE-2025-6205 is a missing authorization flaw (CWE-862) in Dassault Systèmes DELMIA Apriso, an enterprise manufacturing execution system (MES), affecting all releases from Release 2020 through Release 2025. Because required authorization checks are absent, a remote attacker can reach affected application functionality without any credentials or user interaction, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation allows the attacker to gain privileged access to the application, with high impact on confidentiality and integrity, earning a critical CVSS 3.1 score of 9.1. Any organization running DELMIA Apriso Release 2020 through Release 2025 is affected, typically manufacturers using Apriso to run plant-floor and production operations. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-10-28 amid reports of active exploitation, and EPSS assigns a 72.2% probability of exploitation within 30 days, though no public proof-of-concept is known. Do: Apply the mitigations or updates specified in Dassault Systèmes' security advisory for all DELMIA Apriso deployments from Release 2020 through Release 2025, as required by CISA's KEV listing (federal agencies must follow BOD 22-01 timelines or discontinue use). Until patched, restrict network access to Apriso application servers and monitor for unauthenticated or unexpected privileged access to the application. Check vendor release notes for the exact fixed release applicable to your installed Apriso release, since the data here does not specify one. | 9.1 group max | 73% | KEV |
| moderate≈1,000–5,000 plant/site deployments of Apriso instances worldwide (exact count unknown) |
Full article530 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 29, 2025Vulnerability / Malware
Threat actors are actively exploiting multiple security flaws impacting Dassault Systèmes DELMIA Apriso and XWiki, according to alerts issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and VulnCheck.
The vulnerabilities are listed below -
- CVE-2025-6204 (CVSS score: 8.0) - A code injection vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to execute arbitrary code.
- CVE-2025-6205 (CVSS score: 9.1) - A missing authorization vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to gain privileged access to the application.
- CVE-2025-24893 (CVSS score: 9.8) - An improper neutralization of input in a dynamic evaluation call (aka eval injection) in XWiki that could allow any guest user to perform arbitrary remote code execution through a request to the "/bin/get/Main/SolrSearch" endpoint.
Both CVE-2025-6204 and CVE-2025-6205 affect DELMIA Apriso versions from Release 2020 through Release 2025. They were addressed by Dassault Systèmes in early August.
According to details shared by ProjectDiscovery researchers Rahul Maini, Harsh Jaiswal, and Parth Malhotra last month, the two security flaws can be fashioned together into an exploit chain to create accounts with elevated privileges and then drop executable files into a web-served directory, resulting in a full application compromise.
Interestingly, the addition of the two shortcomings to the Known Exploited Vulnerabilities (KEV) catalog comes a little over a month after CISA flagged the exploitation of another critical flaw in the same product (CVE-2025-5086, CVSS score: 9.0), a week after the SANS Internet Storm Center detected in-the-wild attempts. It's currently not known if these efforts are related.
VulnCheck, which first detected exploitation attempts targeting CVE-2025-24893 on October 24, 2025, said the vulnerability is being abused as part of a two-stage attack chain that delivers a cryptocurrency miner. According to CrowdSec and Cyble, the vulnerability is said to have been weaponized in real-world attacks as far back as March 2025.
"We observed multiple exploit attempts against our XWiki canaries coming from an attacker geolocated in Vietnam," VulnCheck's Jacob Baines said. "The exploitation proceeds in a two-pass workflow separated by at least 20 minutes: the first pass stages a downloader (writes a file to disk), and the second pass later executes it."
The payload uses wget to retrieve a downloader ("x640") from "193.32.208[.]24:8080" and write it to the "/tmp/11909" location. The downloader, in turn, runs shell commands to fetch two additional payloads from the same server -
- x521, which fetches the cryptocurrency miner located at "193.32.208[.]24:8080/rDuiQRKhs5/tcrond"
- x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration
The attack traffic, per VulnCheck, originates from an IP address that geolocates to Vietnam ("123.25.249[.]88") and has been flagged as malicious in AbuseIPDB for engaging in brute-force attempts as recently as October 26, 2025.
In light of active exploitation, users are advised to apply the necessary updates as soon as possible to safeguard against threats. Several Civilian Executive Branch (FCEB) agencies are required to remediate the DELMIA Apriso flaws by November 18, 2025.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html