← Vulnerability feed

Vulnerability record · CVE-2025-6204 · published 4 August 2025

CVE-2025-6204: DELMIA Apriso code injection allows arbitrary code execution

3ds · Delmia Apriso

DELMIA Apriso Releases 2020 through 2025 contain an improper control of code generation (code injection) flaw, CWE-94, that can let an attacker execute arbitrary code. The vulnerability is network reachable but requires high privileges and has high attack complexity, so it matters most for environments where an authenticated high-privilege account can be abused or compromised.

8.0 CVSS 3.1 High CISA KEV since 28 Oct 2025 EPSS 78% · top 0.4% CWE-94 · Code injection
8.0CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityThe flaw allows arbitrary code execution, is listed in CISA KEV as exploited in the wild, and has a very high EPSS probability, despite requiring high privileges and high attack complexity.

What it is

DELMIA Apriso Releases 2020 through 2025 contain an improper control of code generation (code injection) flaw, CWE-94, that can let an attacker execute arbitrary code. The vulnerability is network reachable but requires high privileges and has high attack complexity, so it matters most for environments where an authenticated high-privilege account can be abused or compromised.

Impact

An attacker who can reach the vulnerable component with sufficient privileges can execute arbitrary code in the context of the affected service, potentially leading to full compromise of the Apriso environment and connected manufacturing operations.

Attack surface

The CVSS vector is AV:N/AC:H/PR:H/UI:N, meaning the flaw is reachable over the network, requires high privileges, and needs no user interaction. No further detail on the exact endpoint or interface is provided in the record.

Exploitation

CVE-2025-6204 is listed in CISA KEV with a due date of 2025-11-18, indicating known exploitation in the wild, and EPSS gives a 30-day probability of 0.77322 (99.531st percentile). The record does not document ransomware campaign use.

What to do

  • Apply the vendor mitigation or fixed release per the Dassault Systèmes security advisory for CVE-2025-6204.
  • Follow CISA BOD 22-01 guidance, including the 2025-11-18 remediation due date, or discontinue use if no mitigation is available.
  • Restrict network access to DELMIA Apriso services and limit high-privilege accounts to only those that require them.
  • Monitor and audit high-privilege account activity for unexpected code execution or configuration changes.
  • If patching cannot be completed immediately, isolate affected Apriso instances from untrusted networks.

Detection

  • Review Apriso and host logs for unexpected process creation or code execution originating from the Apriso service account.
  • Alert on anomalous activity by high-privilege Apriso accounts, especially outside normal maintenance windows.
  • Monitor network traffic to Apriso endpoints for exploitation attempts against the vulnerable component.
  • Correlate CISA KEV and EPSS signals with asset inventory to confirm exposure and prioritize remediation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-6204 to the Known Exploited Vulnerabilities catalog on 28 October 2025 as "Dassault Systèmes DELMIA Apriso Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 November 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6204 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2025-6205DELMIA Apriso missing authorization allows privileged accessDELMIA Apriso Releases 2020 through 2025 contain a missing authorization flaw (CWE-862) that lets an attacker obtain privileged access to the applica…KEVEPSS 73%analysed9.0CVE-2025-5086DELMIA Apriso deserialization of untrusted data enables remote code executionDELMIA Apriso from Release 2020 through Release 2025 contains a deserialization of untrusted data flaw (CWE-502) that can lead to remote code executi…KEVEPSS 97%analysed8.8CVE-2023-21413ds delmia apriso deserialization of untrusted data vulnerabilityAn unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.EPSS 1.0%7.5CVE-2024-09353ds delmia apriso sensitive information in log file vulnerabilityInsertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.35%7.5CVE-2023-21403ds delmia apriso server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue reque…EPSS 0.56%6.1CVE-2023-21393ds delmia apriso cross-site scripting vulnerabilityA reflected Cross-site Scripting (XSS) Vulnerability in DELMIA Apriso Release 2017 through Release 2022 allows an attacker to execute arbitrary scrip…EPSS 0.35%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed

Source: NIST National Vulnerability Database (record CVE-2025-6204), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.