Vulnerabilidades en Dassault Systèmes

102 resultados
Análisis Vexday

O portfólio da Dassault Systèmes acumula 98 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa que está 6,8 vezes acima da média geral do catálogo, sinalizando risco operacional elevado para ambientes que utilizam essas soluções. A CVE mais crítica no momento, CVE-2025-5086, apresenta EPSS de 0,89, indicando probabilidade muito alta de exploração iminente e demandando atenção prioritária de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere lacunas persistentes em validação de entrada e saída nas aplicações do vendor. Com 8 CVEs de severidade crítica e 6 surgidas nos últimos 90 dias, a superfície de ataque permanece ativa e requer monitoramento contínuo.

CVE-2025-5086CRITICALDeserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025EPSS 89.8%KEVCVE-2025-6204HIGHImproper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025EPSS 76.1%KEVCVE-2025-6205CRITICALMissing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025EPSS 71.1%KEVCVE-2024-3300CRITICALPre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024EPSS 2.8%CVE-2024-1624CRITICALOS Command Injection vulnerability affecting documentation server on certain Releases of 3DEXPERIENCE, SIMULIA Abaqus, SIMULIA Isight and CATIA ComposerEPSS 2.1%CVE-2023-1997HIGHOS Command Injection vulnerability affecting SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023xEPSS 1.7%CVE-2023-6078HIGHOS Command Injection vulnerability affecting BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023EPSS 1.6%CVE-2023-2141HIGHUnsafe .NET object deserialization affecting DELMIA Apriso Release 2017 through Release 2022 EPSS 1.0%CVE-2023-1287CRITICALENOVIA Live Collaboration V6R2013xE is affected by an XSL template injection vulnerabilityEPSS 1.0%CVE-2025-9976CRITICALOS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.9%CVE-2024-3301HIGHPost-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.7%CVE-2023-2140HIGHServer-Side Request Forgery vulnerability affecting DELMIA Apriso Release 2017 through Release 2022 EPSS 0.6%CVE-2026-7858CRITICALDeserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026xEPSS 0.5%CVE-2023-1288MEDIUMENOVIA Live Collaboration V6R2013xE is affected by an XML External Entity injection (XXE) vulnerabilityEPSS 0.5%CVE-2026-11756CRITICALDeserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026xEPSS 0.5%CVE-2024-12089HIGHStored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.4%CVE-2023-5599MEDIUMStored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023xEPSS 0.4%CVE-2023-5598MEDIUMStored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023xEPSS 0.4%CVE-2026-10094CRITICALPath Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026EPSS 0.4%CVE-2024-6378HIGHReflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.4%