Dassault's vulnerability footprint centers on its 3DEXPERIENCE platform, a broadly deployed product-lifecycle and collaboration suite used across engineering and manufacturing organizations. The observed exposure recurs through cross-site scripting weaknesses in web-facing components, a characteristic vulnerability class for large web-integrated enterprise applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dassault over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5599MEDIUM A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allows an attacker to execu | Nov 21, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-5598MEDIUM Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allow an attacker to execute arb | Nov 21, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dassault.
Media articles that mention a CVE ID that affects a product developed by Dassault — matched by CVE ID, not by vendor name.