Vulnerability record · CVE-2025-6204 · published 4 August 2025
CVE-2025-6204: DELMIA Apriso code injection allows arbitrary code execution
3ds · Delmia Apriso
DELMIA Apriso Releases 2020 through 2025 contain an improper control of code generation (code injection) flaw, CWE-94, that can let an attacker execute arbitrary code. The vulnerability is network reachable but requires high privileges and has high attack complexity, so it matters most for environments where an authenticated high-privilege account can be abused or compromised.
Description
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows arbitrary code execution, is listed in CISA KEV as exploited in the wild, and has a very high EPSS probability, despite requiring high privileges and high attack complexity.
What it is
DELMIA Apriso Releases 2020 through 2025 contain an improper control of code generation (code injection) flaw, CWE-94, that can let an attacker execute arbitrary code. The vulnerability is network reachable but requires high privileges and has high attack complexity, so it matters most for environments where an authenticated high-privilege account can be abused or compromised.
Impact
An attacker who can reach the vulnerable component with sufficient privileges can execute arbitrary code in the context of the affected service, potentially leading to full compromise of the Apriso environment and connected manufacturing operations.
Attack surface
The CVSS vector is AV:N/AC:H/PR:H/UI:N, meaning the flaw is reachable over the network, requires high privileges, and needs no user interaction. No further detail on the exact endpoint or interface is provided in the record.
Exploitation
CVE-2025-6204 is listed in CISA KEV with a due date of 2025-11-18, indicating known exploitation in the wild, and EPSS gives a 30-day probability of 0.77322 (99.531st percentile). The record does not document ransomware campaign use.
What to do
- Apply the vendor mitigation or fixed release per the Dassault Systèmes security advisory for CVE-2025-6204.
- Follow CISA BOD 22-01 guidance, including the 2025-11-18 remediation due date, or discontinue use if no mitigation is available.
- Restrict network access to DELMIA Apriso services and limit high-privilege accounts to only those that require them.
- Monitor and audit high-privilege account activity for unexpected code execution or configuration changes.
- If patching cannot be completed immediately, isolate affected Apriso instances from untrusted networks.
Detection
- Review Apriso and host logs for unexpected process creation or code execution originating from the Apriso service account.
- Alert on anomalous activity by high-privilege Apriso accounts, especially outside normal maintenance windows.
- Monitor network traffic to Apriso endpoints for exploitation attempts against the vulnerable component.
- Correlate CISA KEV and EPSS signals with asset inventory to confirm exposure and prioritize remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-6204 to the Known Exploited Vulnerabilities catalog on 28 October 2025 as "Dassault Systèmes DELMIA Apriso Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 November 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6204 | US Government Resource |
Track CVE-2025-6204 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-6204), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.