Executive Summary
In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso (CVE-2025-6204 and CVE-2025-6205) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild. The code injection and missing authorization flaws present serious security bypass opportunities, allowing malicious actors to achieve unauthorized access and potentially execute arbitrary code. These weaknesses have become high-value targets for cyber attackers, potentially threatening sensitive enterprise manufacturing and operational data integrity across organizations that have yet to apply available patches.
This incident underscores the growing trend of rapid exploitation of industrial software vulnerabilities by sophisticated threat actors. With regulatory frameworks such as BOD 22-01 placing increasing responsibility on federal agencies to remediate such vulnerabilities quickly, all organizations must adapt their patch management and risk processes to respond to elevated attacker velocity.
Why This Matters Now
The exploitation of these DELMIA Apriso vulnerabilities demonstrates how attackers continue to pivot towards supply chain and industrial software targets. Immediate action is required because active exploits are circulating, magnifying the risk of large-scale compromise across critical sectors reliant on manufacturing automation systems.
Attack Path Analysis
The attacker exploited the newly disclosed DELMIA Apriso vulnerabilities to gain initial access to enterprise cloud environments. Once inside, they escalated privileges by abusing authorization flaws to obtain higher access levels. The adversary then moved laterally across cloud workloads, targeting other systems and sensitive data stores. With privileged access, they established a command and control channel using allowed outbound connections and covert techniques. Data was exfiltrated through permitted egress paths, followed by potential business disruption or data tampering as the final impact.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited CVE-2025-6204 (code injection) via a vulnerable DELMIA Apriso internet-facing interface to gain unauthorized entry.
Related CVEs
CVE-2025-6204
CVSS 8A code injection vulnerability in DELMIA Apriso versions 2020 through 2025 allows authenticated attackers to execute arbitrary code.
Affected Products:
Dassault Systèmes DELMIA Apriso – 2020, 2021, 2022, 2023, 2024, 2025
Exploit Status:
exploited in the wildCVE-2025-6205
CVSS 9.1A missing authorization vulnerability in DELMIA Apriso versions 2020 through 2025 allows unauthenticated attackers to gain privileged access.
Affected Products:
Dassault Systèmes DELMIA Apriso – 2020, 2021, 2022, 2023, 2024, 2025
Exploit Status:
exploited in the wildCVE-2025-5086
CVSS 9A deserialization of untrusted data vulnerability in DELMIA Apriso versions 2020 through 2025 could lead to remote code execution.
Affected Products:
Dassault Systèmes DELMIA Apriso – 2020, 2021, 2022, 2023, 2024, 2025
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Process Injection
Phishing
Exploitation for Privilege Escalation
Valid Accounts
Exploitation for Defense Evasion
Hardware Additions
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Remediate Security Vulnerabilities
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 8
CISA Zero Trust Maturity Model 2.0 – Vulnerability Management & Remediation
Control ID: Asset Management Capability
NIS2 Directive – Risk Assessment and Vulnerability Handling
Control ID: Article 21(2)–(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Automotive
Dassault Systèmes DELMIA Apriso vulnerabilities directly impact manufacturing operations, exposing production lines to code injection attacks and unauthorized access breaches.
Aviation/Aerospace
Critical aerospace manufacturing systems using DELMIA Apriso face severe risks from CVE-2025-6204/6205 exploits, threatening production security and regulatory compliance requirements.
Defense/Space
Defense contractors utilizing Dassault manufacturing platforms are vulnerable to active exploitation targeting industrial control systems and sensitive production data exfiltration.
Government Administration
Federal agencies must remediate DELMIA Apriso vulnerabilities by BOD 22-01 requirements, protecting government manufacturing operations from known exploited attack vectors.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2025/10/28/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- Dassault Systèmes Security Advisory for CVE-2025-6204https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204Verified
- Dassault Systèmes Security Advisory for CVE-2025-6205https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6205Verified
- CISA Adds One Known Exploited Vulnerability to Cataloghttps://www.cisa.gov/news-events/alerts/2025/09/11/cisa-adds-one-known-exploited-vulnerability-catalogVerified
- Dassault Systèmes Security Advisory for CVE-2025-5086https://www.3ds.com/trust-center/security/security-advisories/cve-2025-5086Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
CNSF controls such as zero trust segmentation, east-west traffic security, egress enforcement, and inline IPS would have limited unauthorized access, lateral movement, covert communications, and data exfiltration in the attack. Continuous anomaly detection and policy-driven isolation would significantly reduce blast radius and speed up detection and response.
Control: Cloud Firewall (ACF)
Mitigation: Detected and blocked initial exploit attempts to exposed interfaces.
Control: Zero Trust Segmentation
Mitigation: Limited scope of privilege escalation by restricting lateral access to privileged resources.
Control: East-West Traffic Security
Mitigation: Blocked unauthorized workload-to-workload movement.
Control: Inline IPS (Suricata)
Mitigation: Detected and prevented known C2 and exploit signatures.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented data exfiltration through policy-driven filtering and inspection.
Rapid identification and containment of malicious actions and abnormal behaviors.
Impact at a Glance
Affected Business Functions
- Manufacturing Operations
- Supply Chain Management
- Quality Assurance
Estimated downtime: 5 days
Estimated loss: $1,000,000
Potential exposure of proprietary manufacturing data and intellectual property.
Recommended Actions
Key Takeaways & Next Steps
- • Immediately patch DELMIA Apriso and prioritize remediation of KEV Catalog vulnerabilities.
- • Enforce zero trust segmentation and east-west workload isolation to limit lateral attacker movement.
- • Deploy egress filtering and inline IPS to detect and block unauthorized outbound and C2 communications.
- • Implement continuous threat detection and anomaly response for rapid identification of compromise.
- • Centralize visibility and policy enforcement across multi-cloud and hybrid environments with Cloud Network Security Framework.



