LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-6205: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 28, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 18, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-6205 to its Known Exploited Vulnerabilities catalog on Oct 28, 2025, with a federal patch deadline of Nov 18, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.

CVE-2025-6205 is a missing authorization vulnerability in Dassault Systèmes DELMIA Apriso. According to CISA, it could allow an attacker to gain privileged access to the application. For teams running manufacturing execution or related industrial software, this matters because elevated access can enable unauthorized configuration changes, data access, or operational interference if the product is reachable by an attacker.

Public detail is limited to the CWE class and the high-level impact described by CISA. Confirm exact scope, affected configurations, and fixes against the vendor advisory before acting.

How it works

The weakness is classified as CWE-862 (Missing Authorization). In this class of flaw, the application fails to properly verify that a user or process is authorized to perform a sensitive action or access a privileged function. An attacker who can reach the vulnerable interface may invoke functionality that should be restricted, potentially obtaining privileged access to the application as described in the CISA summary.

No public exploit mechanics, attack vectors, or prerequisites beyond the general missing-authorization pattern are provided in the available facts. Defenders should treat any network-accessible or authenticated entry points to DELMIA Apriso as potentially relevant and verify details against the vendor advisory rather than assuming a specific exploitation path.

Am I affected? How to find it in your systems

DELMIA Apriso is typically deployed in manufacturing and operations environments as part of manufacturing execution system (MES) or related production-management stacks. It may run on-premises or in cloud-hosted configurations.

How to remediate

Patch first. Apply the mitigations and updates specified by Dassault Systèmes for DELMIA Apriso. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Implement compensating controls to reduce exposure until the vendor update can be applied.

These steps reduce risk but do not replace the vendor fix. Plan to patch as soon as feasible.

If your data may have been exposed

Vulnerabilities that grant privileged access can lead to unauthorized data access or broader compromise if exploited. Known ransomware use of this CVE is not documented in the provided facts. If you suspect exposure, review application and infrastructure logs for signs of unauthorized privileged activity, isolate affected systems, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to check whether credentials or related information have appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDassault Systèmes · DELMIA Apriso
WeaknessCWE-862
Added to CISA KEVOct 28, 2025
Federal patch deadlineNov 18, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities