🟡 CVE-2025-6204

Code injection vulnerability in Dassault Systèmes DELMIA Apriso manufacturing operations management platform allows arbitrary code execution. Requires high privileges but exploitable over network without user interaction.

← Back to Overview
MEDIUM_RISK
Risk Level
8.0
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
MEDIUM
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: MEDIUM

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-08-04

Added to CISA KEV: 2025-10-28 85 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2025-10-30)

Here's what is known about the CVE-2025-6204 vulnerability:

  • Affected Applications/Services: The vulnerability affects Dassault Systèmes DELMIA Apriso versions from Release 2020 through Release 2025 [5][4].
  • Active Exploitation: CVE-2025-6204 is being actively exploited in the wild [1].
  • CISA KEV Status: CISA has added CVE-2025-6204 to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation [3][1]. This means that CISA has determined that this vulnerability poses a significant risk and is being actively used in attacks [2].
  • Vulnerability Type: CVE-2025-6204 is a code injection vulnerability [6][7].
  • Attack Vector: An attacker could exploit this vulnerability to execute arbitrary code [6][4].
  • Chaining: CVE-2025-6204 can be chained with other vulnerabilities (e.g., CVE-2025-6205) for greater impact. For example, CVE-2025-6205 could be used to create new credentials, which could then be used in conjunction with CVE-2025-6204 to upload a malicious file [1].

Sources

  1. Two additional flaws in Dassault Systèmes DELMIA Apriso exploited

    For example, after using CVE-2025-6205 to create new credentials, the attacker would be able to leverage CVE-2025-6204 to upload a malicious file ...

  2. CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its KEV Catalog, based on evidence of active exploitation. ... CVE-2025-6204 Dassault Systèmes DELMIA ...

  3. CVE-2025-6204 - Exploits & Severity - Feedly

    CVE-2025-6204 - DELmia Apriso Code Injection Vulnerability. Latest Vulnerabilities / 1h.4, 2025, 10:15 a.m. 31 minutes ago Description : An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to…

  4. Known Exploited Vulnerabilities Catalog

    CVE-2025-6204. Dassault Systèmes DELMIA Apriso Code Injection Vulnerability: Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could ...

  5. The Hacker News | #1 Trusted Source for Cybersecurity News

    CVE-2025-6205 (CVSS score: 9.1) - A missing authorization vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to gain privileged access to the application. CVE-2025-24893 (CVSS score: 9.8) - An improper neutralization of input in a dynamic evaluation call (aka eval injectio…

  6. Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws ...

    CVE-2025-6204 (CVSS score: 8.0) - A code injection vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to execute arbitrary code. CVE-2025-6205 (CVSS score: 9.1) - A missing authorization vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to gain…

  7. CVE-2025-6204

    Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025.