U.S. CISA adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog
美国CISA将达索系统DELMIA Apriso平台的两个高危漏洞(CVE-2025-6204和CVE-2025-6205)加入已知被利用漏洞目录。前者为代码注入漏洞(CVSS 8.0),后者为缺少授权问题(CVSS 9.1),影响Release 2020至Release 2025版本。CISA要求联邦机构于2025年11月18日前修复,并建议私营组织跟进。此前CISA已将该平台另一高危漏洞CVE-2025-5086纳入目录。 2025-10-29 08:39:37 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

U.S. CISA adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Oracle, Windows, Kentico, and Apple flaws to its Known Exploited Vulnerabilities (KEV) catalog.

  • CVE-2025-6204 Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
  • CVE-2025-6205 Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

Dassault Systèmes DELMIA Apriso is a Manufacturing Operations Management (MOM) and Manufacturing Execution System (MES) platform. It helps manufacturers digitally manage, monitor, and optimize production and logistics operations across plants and global supply chains.

  • CVE-2025-6204 (CVSS score: 8.0) – A code injection vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to execute arbitrary code. The flaw impacts Release 2020 through Release 2025
  • CVE-2025-6205 (CVSS score: 9.1) – A missing authorization vulnerability in Dassault Systèmes DELMIA Apriso from Release 2020 through Release 2025. An attacker could exploit the flaw to gain privileged access to the application.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by November 18, 2025.

In September, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another Dassault Systèmes DELMIA Apriso flaw, tracked as CVE-2025-5086 (CVSS score of 9.0), to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is a deserialization of untrusted data issue affecting DELMIA Apriso from Release 2020 through Release 2025. An attacker could trigger the flaw to execute arbitrary code remotely.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)




文章来源: https://securityaffairs.com/183990/security/u-s-cisa-adds-dassault-systemes-delmia-apriso-flaws-to-its-known-exploited-vulnerabilities-catalog.html
如有侵权请联系:admin#unsafe.sh