Pre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
CVE-2024-3300
9CRITICAL
What is CVE-2024-3300?
This vulnerability arises from unsafe .NET object deserialization present in the DELMIA Apriso software platform developed by Dassault Systèmes. Affected versions span from Release 2019 to Release 2024. Exploitation of this weakness allows for pre-authentication remote code execution, posing significant risks to the security of systems leveraging this software. Proper measures should be taken to update and secure systems against potential exploits related to this vulnerability.
Affected Version(s)
DELMIA Apriso Release 2019 Golden
DELMIA Apriso Release 2020 Golden
DELMIA Apriso Release 2021 Golden
References
EPSS Score
43% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mehdi Elyassa of Synacktiv