← Back to CVE List
Vulnerability Intelligence Report
Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025

CVE-2025-6204

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CISA KEV Nuclei Template SSVC: Active Exploitation
CVSS Base Score
8.0
HIGH
Exploitability:1.4
Impact Score:6.1
EPSS Probability:75.31%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
Dassault Systèmes DELMIA Apriso Release 2020 Golden <= Release 2020 SP4 (affected), Release 2021 Golden <= Release 2021 SP3 (affected), Release 2022 Golden <= Release 2022 SP3 (affected), Release 2023 Golden <= Release 2023 SP3 (affected), Release 2024 Golden <= Release 2024 SP1 (affected), Release 2025 Golden <= Release 2025 SP1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
75.306%

Identity & Timeline

StatusPUBLISHED
Assigning Authority3DS
Reserved2025-06-17T14:03:08
Published2025-08-04T09:14:08
Last Updated2026-02-26T17:50:03

LINK COPIED TO CLIPBOARD