Impact
A vulnerability in the Station Launcher App of the 3DEXPERIENCE platform allows deserialization of untrusted data, which can enable an unauthenticated attacker to execute arbitrary code. The flaw is a classic Deserialization of Untrusted Data weakness, classified as CWE-502, and it could compromise confidentiality, integrity, and availability of the affected application and any systems it orchestrates.
Affected Systems
The flaw affects Dassault Systèmes' Station Launcher App within the 3DEXPERIENCE platform for all releases from R2023x through R2026x. Users running any of these releases should check whether their instance includes the unpatched component.
Risk and Exploitability
The vulnerability scores a maximum CVSS score of 10, indicating critical severity. The EPSS score of less than 1% suggests a low current exploitation probability, and it is not listed in CISA’s KEV catalog. However, a remote attacker could potentially exploit the flaw by sending crafted serialized data to the shared service, bypassing authentication controls. The likely attack vector is network-based delivery of malicious payloads to the Station Launcher App over the exposed interfaces.
OpenCVE Enrichment