Skip to content
COOEY

FAIL › dossier

DELMIA Apriso

PRODUCT

· dossier confidence 0%

DELMIA Apriso has experienced multiple, actively exploited remote code execution vulnerabilities in late 2025, highlighting significant security weaknesses and a potential risk to manufacturing operations. This pattern suggests a need for immediate remediation and a review of security practices.

PROFILE
CategoryManufacturing SoftwareWhat they doDELMIA Apriso is a manufacturing operations management (MOM) software suite used for production planning, execution, and tracking. It helps manufacturers optimize their processes and improve efficiency.
SECURITY POSTURE

DELMIA Apriso has demonstrated a concerning pattern of remote code execution vulnerabilities, indicating potential weaknesses in its security development lifecycle. The repeated exploitation of these vulnerabilities in the wild suggests inadequate patching and/or insufficient security controls.

Notable failures
  • Unpatched code injection vulnerability (CVE-2025-6204)
  • Unpatched authorization vulnerability (CVE-2025-6205)
  • Remote code execution vulnerability (CVE-2025-5086)
Patterns: Repeated RCE vulnerabilities; Lack of timely patching; Insufficient authorization controls
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2025-10-28 CVE-2025-6204 high Dassault Systèmes' DELMIA Apriso had an unpatched code injection vulnerability exploited in the wild, allowing attackers to execute arbitrary code.
2025-10-28 CVE-2025-6205 high Dassault Systèmes DELMIA Apriso had an unpatched authorization vulnerability exploited in the wild, allowing attackers to gain privileged access.
2025-09-11 CVE-2025-5086 high Dassault Systèmes' DELMIA Apriso software had a remote code execution vulnerability actively exploited in the wild
Open questions: What is the current patching status of CVE-2025-6204, CVE-2025-6205, and CVE-2025-5086? · What are the root causes of the repeated RCE vulnerabilities? · What security awareness and training programs are in place for DELMIA Apriso development and maintenance teams?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:16:23.884177+00:00