The Containment Era is here. →Explore

Executive Summary

In June 2024, CISA issued an alert highlighting active exploitation of two vulnerabilities (CVE-2024-22120 and CVE-2024-22121) within Dassault Systèmes’ DELMIA Apriso platform, a widely used manufacturing operations management solution. The flaws, found in DELMIA Apriso Release 2017 to 2023, allow unauthenticated attackers to execute remote code, potentially compromising production environments and exposing sensitive operational data. Attackers are leveraging these vulnerabilities to target the manufacturing sector for automated ransomware deployment and data exfiltration, resulting in operational disruption and risk to production integrity.

This incident underscores the trend of threat actors focusing on supply chain and OT/IT hybrid platforms, exploiting unpatched flaws for initial access. The urgent CISA advisory signals accelerating regulatory scrutiny and highlights the increased risks posed by software supply chain weaknesses in critical infrastructure sectors.

Why This Matters Now

Threat actors are increasingly exploiting unpatched vulnerabilities in mission-critical industrial management software, putting manufacturers at heightened risk of operational shutdowns, ransomware, and data breaches. Immediate remediation is crucial as regulatory bodies intensify alerts and attackers accelerate exploitation campaigns targeting supply chain and manufacturing ecosystems.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers exploited CVE-2024-22120 and CVE-2024-22121 in DELMIA Apriso, enabling unauthenticated remote code execution and compromising operational systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, microsegmentation, east-west traffic controls, and egress policy enforcement—specifically as delivered by CNSF-aligned controls—could have detected, limited, or outright prevented attacker movement and data loss following exploitation of these vulnerabilities.

Initial Compromise

Control: Inline IPS (Suricata)

Mitigation: Prevented or detected inbound exploit attempts.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Constrained lateral privilege escalation through strict identity-based policy.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked unauthorized east-west movement.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Restricted outbound traffic to known, allowed destinations.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Observed or prevented unapproved data exfiltration in encrypted channels.

Impact (Mitigations)

Detected and responded to anomalous or destructive behaviors.

Impact at a Glance

Affected Business Functions

  • Manufacturing Operations Management
  • Production Scheduling
  • Quality Management
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive manufacturing data, including production schedules and quality control records.

Recommended Actions

  • Apply inline IPS and virtual patching at the cloud perimeter to block exploitation of known vulnerabilities.
  • Enforce Zero Trust segmentation and strict identity-based access policies to minimize lateral attacker movement.
  • Activate robust east-west traffic monitoring and microsegmentation to promptly detect anomalous internal activity.
  • Implement comprehensive egress filtering and encrypted traffic monitoring to prevent C2 and data exfiltration.
  • Enable real-time threat detection and automate incident response workflows to contain potential ransomware or destructive operations.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image