peter bassill · operator
$ cve CVE-2025-6204 JSON

CVE-2025-6204 KEV

8.0
HIGH · CVSS 3.1 · EPSS 78% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-11-18.

Description

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

Scoring

CVSS8.0 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS77.96% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2025-11-18
Public exploitnone known
Published2025-08-04
Last modified2026-06-17

CISA KEV

NameDassault Systèmes DELMIA Apriso Code Injection Vulnerability
Added2025-10-28
Due2025-11-18
Vendor / productDassault Systèmes / DELMIA Apriso
Ransomware usenone reported

Affected (1)

VendorProduct
3dsdelmia apriso

References

→ the Explorer  ·  watch your stack  ·  NVD