Impact
The vulnerability is an Improper Authentication flaw that allows an attacker to bypass the standard login process for DELMIA Apriso, giving them privileged access to the server. The weakness is categorized as CWE-287.
Affected Systems
Dassault Systèmes DELMIA Apriso releases from 2020 through 2026 are affected. Any deployment of these releases without the vendor patch is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 reflects critical severity. The EPSS score of < 1% shows a very low probability of exploitation, though exploitation remains possible. The vulnerability is not listed in CISA KEV, indicating no known publicly reported exploits. Based on the description, the attack vector involves interfacing with the authentication mechanism of the Apriso server, and the attacker requires network access to the service; no additional prerequisites are noted.
OpenCVE Enrichment