CVE-2025-6205 is a critical missing authorization vulnerability affecting DELMIA Apriso versions from Release 2020 through Release 2025, allowing an attacker to gain privileged access to the application. Rated 9.1 CRITICAL on CVSS, it can be exploited remotely without authentication or user interaction, posing a high risk to confidentiality and integrity. This vulnerability is actively exploited and listed in CISA's KEV catalog, with significant community discussion and media coverage, although public exploit modules like Metasploit are not yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2020, < 2025CPE matchmatch criteria | cpe:2.3:a:3ds:delmia_apriso:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.