CVE Explorer
CVE-2025-9976
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Station Launcher App in 3DEXPERIENCE platform","vendor":"Dassault Systèmes","versions":[{"lessThanOrEqual":"Release 3DEXPERIENCE R2022x.FP.CFA.2540","status":"affected","version":"Release 3DEXPERIENCE R2022x Golden","versionType":"custom"},{"lessThanOrEqual":"Release 3DEXPERIENCE R2023x.FP.CFA.2532","status":"affected","version":"Release 3DEXPERIENCE R2023x Golden","versionType":"custom"},{"lessThanOrEqual":"Release 3DEXPERIENCE R2024x.FP.CFA.2537","status":"affected","version":"Release 3DEXPERIENCE R2024x Golden","versionType":"custom"},{"lessThanOrEqu…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a00ebfcdb895bbc498ebdea07c05e418aeeb4ed6ea8a72c9806e122c6f4fa8c7 · sha256:271f14e76eb1b4e6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a00ebfcdb895bbc498ebdea07c05e418aeeb4ed6ea8a72c9806e122c6f4fa8c7 · sha256:271f14e76eb1b4e6… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a00ebfcdb895bbc498ebdea07c05e418aeeb4ed6ea8a72c9806e122c6f4fa8c7 · sha256:271f14e76eb1b4e6… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2025-9976"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a00ebfcdb895bbc498ebdea07c05e418aeeb4ed6ea8a72c9806e122c6f4fa8c7 · sha256:271f14e76eb1b4e6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.