PT-2025-23551 · Dsi · Delmia Apriso

Hacktron Ai

·

Published

2025-06-02

·

Updated

2025-10-29

·

CVE-2025-5086

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DELMIA Apriso versions 2020 through 2025
Description DELMIA Apriso is affected by a deserialization of untrusted data issue that could lead to remote code execution. This vulnerability is actively exploited and has been observed in attacks utilizing malicious SOAP requests delivering .NET payloads. Exploitation has been traced to Mexico and involves the use of the Trojan.MSIL.Zapchast.gen malware. The vulnerability impacts industries such as aerospace, automotive, manufacturing, and industrial machinery. CISA has added this vulnerability, tracked as CVE-2025-5086, to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal agencies to patch or mitigate by October 2nd. The vulnerability allows unauthenticated attackers to execute code remotely.
Recommendations Apply vendor patches for DELMIA Apriso versions 2020 through 2025. Validate deserialized data to prevent malicious payloads from being processed. As a temporary workaround, discontinue usage of DELMIA Apriso versions 2020 through 2025 if a patch is unavailable.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-06367
CVE-2025-5086

Affected Products

Delmia Apriso