CVE Explorer
CVE-2025-6205
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"DELMIA Apriso","vendor":"Dassault Systèmes","versions":[{"lessThanOrEqual":"Release 2020 SP4","status":"affected","version":"Release 2020 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2021 SP3","status":"affected","version":"Release 2021 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2022 SP3","status":"affected","version":"Release 2022 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2023 SP3","status":"affected","version":"Release 2023 Golden","versionType":"custom"},{"lessThanOrEqual":"Release 2024 SP1","status":…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:04ed338ee1b1fac310625868d42c7ab63f54b782bc534a34742c36a1b964a028 · sha256:93b51d4fde49aa11… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:04ed338ee1b1fac310625868d42c7ab63f54b782bc534a34742c36a1b964a028 · sha256:93b51d4fde49aa11… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:04ed338ee1b1fac310625868d42c7ab63f54b782bc534a34742c36a1b964a028 · sha256:93b51d4fde49aa11… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-862"],"dateAdded":"2025-10-28","dueDate":"2025-11-18","knownRansomwareCampaignUse":"Unknown","notes":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6205 ; https://nvd.nist.gov/vuln/detail/CVE-2025-6205","product":"DELMIA Apriso","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged …
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:92660d7917bb60bb60deb3a3244d7742e25d754875491fde5423fd8b9c4ffb83 · sha256:16acee8334e59e44… · /vulnerabilities/207Open source location →
{"cwes":["CWE-862"],"dateAdded":"2025-10-28","dueDate":"2025-11-18","knownRansomwareCampaignUse":"Unknown","notes":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6205 ; https://nvd.nist.gov/vuln/detail/CVE-2025-6205","product":"DELMIA Apriso","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged …
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:181ba78ac5e3663c3baa0bc67c6ba884629684ac5e5578859a6a67b6511b50b3 · sha256:635dff916c4092c0… · /vulnerabilities/210Open source location →
Source references
2 source assertions{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6205"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:04ed338ee1b1fac310625868d42c7ab63f54b782bc534a34742c36a1b964a028 · sha256:93b51d4fde49aa11… · /containers/cna/references/0
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6205"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:04ed338ee1b1fac310625868d42c7ab63f54b782bc534a34742c36a1b964a028 · sha256:93b51d4fde49aa11… · /containers/adp/0/references/0
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.