Skip to content
COOEY

FAIL › dossier

Dassault Systèmes

VENDOR

· dossier confidence 80%

Dassault Systèmes has experienced multiple, actively exploited remote code execution vulnerabilities in its DELMIA Apriso software, raising concerns about their software development lifecycle and vulnerability management practices. This necessitates a thorough review of their security posture and patching processes to mitigate future risks.

PROFILE
CategorySoftwareWhat they doDassault Systèmes develops 3D design, simulation, and product lifecycle management solutions including CATIA and SolidWorks. The company offers software solutions and services worldwide.HQVelizy-Villacoublay, FranceSizeLarge (31.46B Market Cap)OwnershipPublic Websitehttps://investor.3ds.com/ ↗
SECURITY POSTURE

Dassault Systèmes has demonstrated a concerning pattern of high-severity remote code execution vulnerabilities within its DELMIA Apriso software. These vulnerabilities have been actively exploited in the wild, indicating insufficient security controls and potentially inadequate patching processes.

Notable failures
  • Unpatched code injection vulnerability (CVE-2025-6204)
  • Unpatched authorization vulnerability (CVE-2025-6205)
  • Remote code execution vulnerability (CVE-2025-5086)
Patterns: Recurring remote code execution vulnerabilities in DELMIA Apriso; Lack of timely patching leading to exploitation in the wild
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2025-10-28 CVE-2025-6204 high Dassault Systèmes' DELMIA Apriso had an unpatched code injection vulnerability exploited in the wild, allowing attackers to execute arbitrary code.
2025-10-28 CVE-2025-6205 high Dassault Systèmes DELMIA Apriso had an unpatched authorization vulnerability exploited in the wild, allowing attackers to gain privileged access.
2025-09-11 CVE-2025-5086 high Dassault Systèmes' DELMIA Apriso software had a remote code execution vulnerability actively exploited in the wild
Open questions: What specific security awareness and training initiatives are being implemented to address the identified vulnerabilities? · What is the root cause analysis for the repeated RCE vulnerabilities in DELMIA Apriso? · What is the current status of patching and remediation for the identified vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:12:08.917295+00:00