References https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204 https://nvd.nist.gov/vuln/detail/CVE-2025-6204 https://projectdiscovery.io/blog/remote-code-execution-in-delmia-apriso https://www.cve.org/CVERecord?id=CVE-2025-6204 https://github.com/advisories/GHSA-xxh4-727v-gjcv https://www.tenable.com/plugins/nessus/272202 https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html https://www.bleepingcomputer.com/news/security/cisa-warns-of-two-more-actively-exploited-dassault-vulnerabilities/ https://www.securityweek.com/cisa-warns-of-exploited-delmia-factory-software-vulnerabilities/ https://access.redhat.com/security/cve/cve-2025-6204
Related Vulnerabilities达索系统DELMIA Apriso存在反序列化漏洞(CVE-2025-5086)(CVE-2025-6205)DELMIA Apriso授权缺失漏洞允许特权访问PoCCVE-2024-3300: Delmia Apriso - Pre-Authentication Unsafe .NET Object DeserializationPoCCVE-2025-5086: Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure DeserializationPoCCVE-2025-6204: DELMIA Apriso - Command InjectionPoCCVE-2025-6205: DELMIA Apriso - Broken Access Control(CVE-2025-5086)DELMIA Apriso未验证的反序列化漏洞导致远程代码执行Dassault Systèmes DELMIA Apriso 日志信息泄露漏洞