Vulnerability record · CVE-2025-6205 · published 4 August 2025
CVE-2025-6205: DELMIA Apriso missing authorization allows privileged access
3ds · Delmia Apriso
DELMIA Apriso Releases 2020 through 2025 contain a missing authorization flaw (CWE-862) that lets an attacker obtain privileged access to the application. Because the check is absent rather than bypassable, any reachable endpoint in the affected code path can be exercised without the intended permission gate. It matters because the product is an enterprise manufacturing operations platform, so privileged access can expose production and business data and functions.
Description
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with no authentication or interaction required, confirmed exploitation via CISA KEV, and very high EPSS probability make this an urgent patch-first item.
What it is
DELMIA Apriso Releases 2020 through 2025 contain a missing authorization flaw (CWE-862) that lets an attacker obtain privileged access to the application. Because the check is absent rather than bypassable, any reachable endpoint in the affected code path can be exercised without the intended permission gate. It matters because the product is an enterprise manufacturing operations platform, so privileged access can expose production and business data and functions.
Impact
An unauthenticated remote attacker gains privileged access to the application, with high confidentiality and integrity impact; availability impact is not scored. That access can be used to read or alter data and functions the attacker should never reach.
Attack surface
Reachable over the network via the application's HTTP interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The record does not identify the specific endpoint or function involved.
Exploitation
CVE-2025-6205 is listed in CISA KEV with a 2025-11-18 remediation due date, indicating exploitation in the wild; EPSS is 0.733 (99.4th percentile). No ransomware campaign use is documented and no public exploit reference is included beyond the vendor advisory and KEV entry.
What to do
- Apply the vendor mitigation or fixed release per the Dassault Systèmes security advisory for CVE-2025-6205; treat this as the first action.
- If no fix is available for your release, follow CISA BOD 22-01 guidance for cloud services or discontinue use of the affected product.
- Restrict network access to DELMIA Apriso interfaces to trusted hosts and segments rather than exposing them broadly.
- Audit and remove unnecessary privileged accounts and review role assignments for the application.
- Track the CISA KEV due date of 2025-11-18 and confirm remediation before it lapses.
Detection
- Review application and web server logs for requests to privileged functions from unauthenticated or unexpected sessions.
- Alert on successful access to administrative or privileged endpoints without a preceding authentication event.
- Baseline normal user-to-function mappings and flag accounts invoking functions outside their assigned role.
- Monitor for new or changed privileged accounts and for configuration changes made outside normal change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-6205 to the Known Exploited Vulnerabilities catalog on 28 October 2025 as "Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 November 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6205 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6205 | US Government Resource |
Track CVE-2025-6205 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-6205), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.