CVE-2025-5086: Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
Other sources
Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of 3DS DELMIA Apriso if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5086?
CVE-2025-5086 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2025-5086?
To fix CVE-2025-5086, update DELMIA Apriso to the latest patched version provided by the vendor.
Which versions of DELMIA Apriso are affected by CVE-2025-5086?
DELMIA Apriso versions from 2020 through 2025 are affected by CVE-2025-5086.
What type of vulnerability is CVE-2025-5086?
CVE-2025-5086 is a deserialization of untrusted data vulnerability.
Can CVE-2025-5086 be exploited remotely?
Yes, CVE-2025-5086 can be exploited remotely, leading to potential unauthorized code execution.