← Vulnerability feed

Vulnerability record · CVE-2025-6205 · published 4 August 2025

CVE-2025-6205: DELMIA Apriso missing authorization allows privileged access

3ds · Delmia Apriso

DELMIA Apriso Releases 2020 through 2025 contain a missing authorization flaw (CWE-862) that lets an attacker obtain privileged access to the application. Because the check is absent rather than bypassable, any reachable endpoint in the affected code path can be exercised without the intended permission gate. It matters because the product is an enterprise manufacturing operations platform, so privileged access can expose production and business data and functions.

9.1 CVSS 3.1 Critical CISA KEV since 28 Oct 2025 EPSS 73% · top 0.6% CWE-862 · Missing authorization
9.1CVSS 3.1 base score
73%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.1 with no authentication or interaction required, confirmed exploitation via CISA KEV, and very high EPSS probability make this an urgent patch-first item.

What it is

DELMIA Apriso Releases 2020 through 2025 contain a missing authorization flaw (CWE-862) that lets an attacker obtain privileged access to the application. Because the check is absent rather than bypassable, any reachable endpoint in the affected code path can be exercised without the intended permission gate. It matters because the product is an enterprise manufacturing operations platform, so privileged access can expose production and business data and functions.

Impact

An unauthenticated remote attacker gains privileged access to the application, with high confidentiality and integrity impact; availability impact is not scored. That access can be used to read or alter data and functions the attacker should never reach.

Attack surface

Reachable over the network via the application's HTTP interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The record does not identify the specific endpoint or function involved.

Exploitation

CVE-2025-6205 is listed in CISA KEV with a 2025-11-18 remediation due date, indicating exploitation in the wild; EPSS is 0.733 (99.4th percentile). No ransomware campaign use is documented and no public exploit reference is included beyond the vendor advisory and KEV entry.

What to do

  • Apply the vendor mitigation or fixed release per the Dassault Systèmes security advisory for CVE-2025-6205; treat this as the first action.
  • If no fix is available for your release, follow CISA BOD 22-01 guidance for cloud services or discontinue use of the affected product.
  • Restrict network access to DELMIA Apriso interfaces to trusted hosts and segments rather than exposing them broadly.
  • Audit and remove unnecessary privileged accounts and review role assignments for the application.
  • Track the CISA KEV due date of 2025-11-18 and confirm remediation before it lapses.

Detection

  • Review application and web server logs for requests to privileged functions from unauthenticated or unexpected sessions.
  • Alert on successful access to administrative or privileged endpoints without a preceding authentication event.
  • Baseline normal user-to-function mappings and flag accounts invoking functions outside their assigned role.
  • Monitor for new or changed privileged accounts and for configuration changes made outside normal change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-6205 to the Known Exploited Vulnerabilities catalog on 28 October 2025 as "Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 November 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6205 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2025-5086DELMIA Apriso deserialization of untrusted data enables remote code executionDELMIA Apriso from Release 2020 through Release 2025 contains a deserialization of untrusted data flaw (CWE-502) that can lead to remote code executi…KEVEPSS 97%analysed8.0CVE-2025-6204DELMIA Apriso code injection allows arbitrary code executionDELMIA Apriso Releases 2020 through 2025 contain an improper control of code generation (code injection) flaw, CWE-94, that can let an attacker execu…KEVEPSS 78%analysed8.8CVE-2023-21413ds delmia apriso deserialization of untrusted data vulnerabilityAn unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.EPSS 1.0%7.5CVE-2024-09353ds delmia apriso sensitive information in log file vulnerabilityInsertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.35%7.5CVE-2023-21403ds delmia apriso server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue reque…EPSS 0.56%6.1CVE-2023-21393ds delmia apriso cross-site scripting vulnerabilityA reflected Cross-site Scripting (XSS) Vulnerability in DELMIA Apriso Release 2017 through Release 2022 allows an attacker to execute arbitrary scrip…EPSS 0.35%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed

Source: NIST National Vulnerability Database (record CVE-2025-6205), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.