CVE-2024-3301 is an unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024, enabling post-authentication remote code execution. With a CVSS score of 8.5 (HIGH), this vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability, though it requires low privileges and high attack complexity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Dassault SystèMes | DELMIA Apriso | >= Release 2019 Golden, <= Release 2019 SP5, >= Release 2020 Golden, <= Release 2020 SP4, >= Release 2021 Golden, <= Release 2021 SP3, >= Release 2022 Golden, <= Release 2022 SP3, >= Release 2023 Golden, <= Release 2023 SP2, >= Release 2024 Golden, <= Release 2024 SP1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.