Pre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
CVE-2024-3300

9CRITICAL

Key Information:

Vendor
CVE Published:
30 May 2024

What is CVE-2024-3300?

This vulnerability arises from unsafe .NET object deserialization present in the DELMIA Apriso software platform developed by Dassault Systèmes. Affected versions span from Release 2019 to Release 2024. Exploitation of this weakness allows for pre-authentication remote code execution, posing significant risks to the security of systems leveraging this software. Proper measures should be taken to update and secure systems against potential exploits related to this vulnerability.

Affected Version(s)

DELMIA Apriso Release 2019 Golden

DELMIA Apriso Release 2020 Golden

DELMIA Apriso Release 2021 Golden

References

EPSS Score

43% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mehdi Elyassa of Synacktiv
.