LiveActive security incident?Get immediate response
CVE Record

CVE-2025-6205: Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

CriticalCVSS 9.1Known exploitedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

DELMIA Apriso has a critical missing authorization flaw that may let an attacker gain privileged application access without credentials or user interaction. CISA lists CVE-2025-6205 in KEV, so exploitation is confirmed by a cited government source. Organizations using affected Apriso releases should treat this as urgent.

Executive priority

Immediate priority for organizations running affected Apriso releases. KEV status means this should not wait for routine patch cycles. Confirm exposure, obtain Dassault remediation guidance, and reduce access while validating whether privileged access misuse occurred.

Technical view

CVE-2025-6205 is CWE-862 in Dassault Systèmes DELMIA Apriso Release 2020 Golden through Release 2025 Golden. CVSS 9.1 indicates network access, low complexity, no privileges, no user interaction, high confidentiality and integrity impact, and no availability impact. Sources do not provide endpoint, module, or proof-of-concept details.

Likely exposure

Exposure is limited to Dassault Systèmes DELMIA Apriso Release 2020 Golden through Release 2025 Golden per the source bundle. The sources do not name CPEs, affected modules, or configuration conditions, so asset owners must verify deployments directly.

Exploitation context

CISA KEV inclusion supports active exploitation. Public source details provided here do not describe exploit mechanics, attacker groups, affected endpoints, or observed campaign patterns. The risk is privileged application access through missing authorization, which can undermine business process integrity.

Researcher notes

Evidence supports critical authorization impact and active exploitation via KEV, but the provided sources omit exploit details, affected endpoints, and fixed version specifics. Validation should stay version-centered and vendor-advisory-centered, with defensive log review for privilege changes or unexpected administrative activity.

Mitigation direction

  • Review the Dassault Systèmes advisory for fixed releases or vendor-approved mitigations.
  • Prioritize remediation under KEV handling timelines and internal critical vulnerability SLAs.
  • Restrict network access to Apriso systems until vendor remediation is confirmed.
  • Audit privileged accounts and authorization-sensitive Apriso activity for anomalies.
  • Ask Dassault support to confirm applicability if release or build status is unclear.

Validation and detection

  • Inventory all DELMIA Apriso deployments and confirm exact release and build status.
  • Check whether any affected Apriso systems are externally or broadly network reachable.
  • Verify the Dassault advisory remediation has been applied or formally accepted as not applicable.
  • Review application and identity logs for unexpected privileged access or role changes.
  • Track CVE-2025-6205 in vulnerability management as CISA KEV and critical severity.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-862: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-6205 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.1 (3.1)
Known Exploited
Yes
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CISA KEV status

Status
Known exploited
Source
CISA / ADP
Date added
Not provided

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.1CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N3.95.2Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

9.1Critical
CVSS 3.1 vector shape for CVE-2025-6205Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Dassault SystèmesDELMIA AprisoRelease 2020 Golden, Release 2021 Golden, Release 2022 Golden, Release 2023 Golden, Release 2024 Golden, Release 2025 Goldenunaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-862 · source CWE mapping

Missing Authorization

Missing Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.