Vulnerabilidades em Dassault Systèmes

102 resultados
Análise Vexday

O portfólio da Dassault Systèmes acumula 98 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa que está 6,8 vezes acima da média geral do catálogo, sinalizando risco operacional elevado para ambientes que utilizam essas soluções. A CVE mais crítica no momento, CVE-2025-5086, apresenta EPSS de 0,89, indicando probabilidade muito alta de exploração iminente e demandando atenção prioritária de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere lacunas persistentes em validação de entrada e saída nas aplicações do vendor. Com 8 CVEs de severidade crítica e 6 surgidas nos últimos 90 dias, a superfície de ataque permanece ativa e requer monitoramento contínuo.

CVE-2024-7737HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.4%CVE-2023-2762HIGHUse-After-Free vulnerability in SLDPRT file reading procedure affecting SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023EPSS 0.4%CVE-2024-3299HIGHOut-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the SLDDRW and SLDPRT file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.4%CVE-2023-2763HIGHUse-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023EPSS 0.4%CVE-2023-1996MEDIUMReflected Cross-site Scripting (XSS) vulnerability affecting Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023xEPSS 0.4%CVE-2023-2139MEDIUMReflected Cross-site Scripting vulnerability affecting DELMIA Apriso Release 2017 through Release 2022 EPSS 0.4%CVE-2024-0935MEDIUMInsertion of Sensitive Information into Log File vulnerabilities affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.4%CVE-2025-4987HIGHStored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025xEPSS 0.4%CVE-2026-9695CRITICALImproper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026EPSS 0.3%CVE-2024-8040HIGHAuthorization Bypass Through User-Controlled Key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-1847HIGHMultiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.3%CVE-2024-12092HIGHStored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-12091HIGHStored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-12090HIGHStored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-3298HIGHOut-Of-Bounds Write and Type Confusion vulnerabilities exist in the DWG and DXF file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.3%CVE-2025-0595HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2025-0827HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3DPlay in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2023-3588MEDIUMStored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022xEPSS 0.3%CVE-2024-7932HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-7939HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024xEPSS 0.3%