CVE Explorer
CVE-2025-6204
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"DELMIA Apriso","vendor":"Dassault Systèmes","versions":[{"lessThanOrEqual":"Release 2020 SP4","status":"affected","version":"Release 2020 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2021 SP3","status":"affected","version":"Release 2021 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2022 SP3","status":"affected","version":"Release 2022 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2023 SP3","status":"affected","version":"Release 2023 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2024 SP1","status":…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1a625cf023621b5e87b8e7254902e435443a66a777024009f557cb724f4d7fd5 · sha256:e7e1a37253f87de8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1a625cf023621b5e87b8e7254902e435443a66a777024009f557cb724f4d7fd5 · sha256:e7e1a37253f87de8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-94","description":"CWE-94 Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a625cf023621b5e87b8e7254902e435443a66a777024009f557cb724f4d7fd5 · sha256:e7e1a37253f87de8… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-94"],"dateAdded":"2025-10-28","dueDate":"2025-11-18","knownRansomwareCampaignUse":"Unknown","notes":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204 ; https://nvd.nist.gov/vuln/detail/CVE-2025-6204","product":"DELMIA Apriso","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code."…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:a40b037311a5eb824b93220d92ad9fa7f20ad5d99a6ab126a2b932f42bfd7c33 · sha256:16acee8334e59e44… · /vulnerabilities/206Open source location →
{"cwes":["CWE-94"],"dateAdded":"2025-10-28","dueDate":"2025-11-18","knownRansomwareCampaignUse":"Unknown","notes":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204 ; https://nvd.nist.gov/vuln/detail/CVE-2025-6204","product":"DELMIA Apriso","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code."…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:3ef5a0570a95dfd68918268ec018980a6dea6f97ade0cbf04a5ab25eb33a4f20 · sha256:635dff916c4092c0… · /vulnerabilities/209Open source location →
Source references
2 source assertions{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a625cf023621b5e87b8e7254902e435443a66a777024009f557cb724f4d7fd5 · sha256:e7e1a37253f87de8… · /containers/cna/references/0
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6204"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a625cf023621b5e87b8e7254902e435443a66a777024009f557cb724f4d7fd5 · sha256:e7e1a37253f87de8… · /containers/adp/0/references/0
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.