Impact
An Improper Authorization flaw in 3DPassport within Dassault Systèmes 3DSwymer can enable an attacker to access user accounts. The vulnerability is defined by CWE‑285 and can lead to unauthorized use of account credentials, potentially granting the attacker further privileges within the system.
Affected Systems
Dassault Systèmes 3DSwymer for releases 3DEXPERIENCE R2023x, R2024x, R2025x, and R2026x are impacted. No older or newer releases are listed as affected.
Risk and Exploitability
The CVSS score of 9.3 highlights severe risk, and an EPSS score is not provided. The flaw is not listed in the CISA KEV catalog. The vulnerability can be exercised by accessing the 3DPassport component over the network, likely from a compromised or malicious user or from within an attacker’s internal network. The attack requires the ability to reach the 3DPassport service and does not explicitly require privilege escalation, meaning attackers with network access could exploit it. Given the high CVSS and lack of mitigation, the potential impact remains high.
OpenCVE Enrichment