Impact
The reported weakness is a deserialization of untrusted data flaw that allows an external actor to modify serialized input and have it executed by SIMULIA Execution Engine. Because the vulnerability does not require prior authentication, an attacker can inject arbitrary code into the engine’s runtime and potentially gain full control over the host system. The weakness is identified as CWE‑502, a common issue where deserializing untrusted data leads to arbitrary code execution.
Affected Systems
Dassault Systèmes SIMULIA Execution Engine in releases from 2023 to 2026 is affected. No specific patch level is listed, so any version within this release range requires remediation.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity, while no EPSS score is published and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw permits unauthenticated remote code execution and the engine is designed for deployment in varied environments, the likelihood of exploitation is high in practice. Attackers would likely exploit remote accessible services that deserialize input without validating the payload.
OpenCVE Enrichment