Dassault Systèmes' DELMIA Apriso, a manufacturing execution system used to run and coordinate production-line operations, had two vulnerabilities confirmed exploited and added to CISA's KEV catalogue on the same day — a code injection bug and a missing authorization flaw, both spanning every release from 2020 through 2025.
| CVE | CVSS | Flaw | Added to KEV |
|---|---|---|---|
| CVE-2025-6205 | 9.1 | Missing authorization | 28 Oct 2025 |
| CVE-2025-6204 | 8.0 | Code injection | 28 Oct 2025 |
Why a five-year release span both being vulnerable is the real story here
Both CVEs affect DELMIA Apriso "from Release 2020 through Release 2025" — meaning the underlying flaws weren't introduced in some recent update and then quickly caught, but appear to have persisted across five consecutive annual release cycles of a platform serious enough to run active manufacturing operations. That kind of longevity in a vulnerability class typically points to something structural: a shared authorization framework or code-generation pathway that carried the same design assumption forward release after release, unexamined, until someone in the field exploited it. For a system that sits at the operational heart of physical production — scheduling work orders, tracking materials, coordinating machinery — a vulnerability with that kind of multi-year reach means a very large population of currently-deployed installations across a very large number of manufacturing sites were exposed simultaneously the moment exploitation was confirmed, regardless of which specific release year any individual plant happened to be running.
Why manufacturing execution systems sit in an unusually consequential category
DELMIA Apriso isn't a back-office application where a breach means stolen records — it's operational technology adjacent software that directly controls or heavily influences physical manufacturing processes. A missing authorization vulnerability that lets an attacker gain privileged access to the application, combined with a code injection bug that lets an attacker execute arbitrary code, together describe a path from unauthorized access straight to arbitrary command execution inside a system with real influence over production-line behavior. Unlike a compromised web application where the worst case is typically data exposure, a compromised manufacturing execution system carries the added risk of physical-world consequences: disrupted production schedules, corrupted quality-control records, or in more severe scenarios, manipulated instructions to physical equipment. That risk profile is precisely why CISA's Known Exploited Vulnerabilities catalogue exists to flag bugs like this with urgency disproportionate to a purely IT-focused reading of the CVSS score alone.
Why the missing authorization bug likely came first in any real exploitation chain
Logically, CVE-2025-6205's missing authorization flaw — gaining privileged access to the application — is the more natural first step in an intrusion, since it's what would let an attacker reach the application surface where CVE-2025-6204's code injection vulnerability could actually be triggered with real effect. Both were added to KEV on the identical date, which strongly suggests they were discovered and reported together as a linked pair rather than as coincidentally simultaneous unrelated findings, reinforcing the reading that they represent two stages of one practical attack path rather than two isolated bugs that happen to share a product.
What to check this week
- Identify every DELMIA Apriso deployment across Release 2020 through Release 2025 specifically, since the affected range spans the platform's entire recent release history rather than one or two isolated versions.
- Apply Dassault Systèmes' vendor advisory patches for both CVE-2025-6204 and CVE-2025-6205 together, treating them as a linked pair given their shared disclosure and KEV-addition date.
- Review manufacturing execution system access logs for privilege escalation patterns predating any observed anomalous code execution, since the authorization bug plausibly precedes the code injection bug in a real attack sequence.
- Loop in operational technology and manufacturing engineering stakeholders, not just the IT security team, given this platform's direct influence over physical production processes.
A final consideration on OT-adjacent software falling outside typical patch cadences
Manufacturing execution systems often sit in a patching blind spot between IT security teams, who may not consider a manufacturing-floor application their asset to track, and operations teams, who may prioritize production uptime over patch windows that require line downtime. This cluster is a reminder that software directly touching physical manufacturing deserves the same confirmed-exploited urgency as any internet-facing enterprise application, and arguably more given the physical-world stakes involved.
How Safeguard helps
Safeguard's continuous inventory extends visibility into operational technology-adjacent software like manufacturing execution systems, ensuring platforms that sit between traditional IT security ownership and operations team priorities don't fall through the cracks of a vulnerability management program built primarily around conventional enterprise applications.