The Containment Era is here. →Explore

Executive Summary

In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso (CVE-2025-6204 and CVE-2025-6205) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild. The code injection and missing authorization flaws present serious security bypass opportunities, allowing malicious actors to achieve unauthorized access and potentially execute arbitrary code. These weaknesses have become high-value targets for cyber attackers, potentially threatening sensitive enterprise manufacturing and operational data integrity across organizations that have yet to apply available patches.

This incident underscores the growing trend of rapid exploitation of industrial software vulnerabilities by sophisticated threat actors. With regulatory frameworks such as BOD 22-01 placing increasing responsibility on federal agencies to remediate such vulnerabilities quickly, all organizations must adapt their patch management and risk processes to respond to elevated attacker velocity.

Why This Matters Now

The exploitation of these DELMIA Apriso vulnerabilities demonstrates how attackers continue to pivot towards supply chain and industrial software targets. Immediate action is required because active exploits are circulating, magnifying the risk of large-scale compromise across critical sectors reliant on manufacturing automation systems.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerabilities highlight gaps in patch management, zero trust segmentation, and the protection of sensitive data in transit, all of which are key requirements in frameworks like NIST 800-53, HIPAA, and PCI DSS.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF controls such as zero trust segmentation, east-west traffic security, egress enforcement, and inline IPS would have limited unauthorized access, lateral movement, covert communications, and data exfiltration in the attack. Continuous anomaly detection and policy-driven isolation would significantly reduce blast radius and speed up detection and response.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Detected and blocked initial exploit attempts to exposed interfaces.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limited scope of privilege escalation by restricting lateral access to privileged resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked unauthorized workload-to-workload movement.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detected and prevented known C2 and exploit signatures.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevented data exfiltration through policy-driven filtering and inspection.

Impact (Mitigations)

Rapid identification and containment of malicious actions and abnormal behaviors.

Impact at a Glance

Affected Business Functions

  • Manufacturing Operations
  • Supply Chain Management
  • Quality Assurance
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $1,000,000

Data Exposure

Potential exposure of proprietary manufacturing data and intellectual property.

Recommended Actions

  • Immediately patch DELMIA Apriso and prioritize remediation of KEV Catalog vulnerabilities.
  • Enforce zero trust segmentation and east-west workload isolation to limit lateral attacker movement.
  • Deploy egress filtering and inline IPS to detect and block unauthorized outbound and C2 communications.
  • Implement continuous threat detection and anomaly response for rapid identification of compromise.
  • Centralize visibility and policy enforcement across multi-cloud and hybrid environments with Cloud Network Security Framework.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image