Vulnerabilities in Dassault Systèmes

102 results
Vexday analysis

O portfólio da Dassault Systèmes acumula 98 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa que está 6,8 vezes acima da média geral do catálogo, sinalizando risco operacional elevado para ambientes que utilizam essas soluções. A CVE mais crítica no momento, CVE-2025-5086, apresenta EPSS de 0,89, indicando probabilidade muito alta de exploração iminente e demandando atenção prioritária de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere lacunas persistentes em validação de entrada e saída nas aplicações do vendor. Com 8 CVEs de severidade crítica e 6 surgidas nos últimos 90 dias, a superfície de ataque permanece ativa e requer monitoramento contínuo.

CVE-2024-7932HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-7736HIGHReflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-8004HIGHStored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-6377HIGHURL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2025-10559HIGHPath Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2024-1848HIGHMultiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024EPSS 0.3%CVE-2025-4992HIGHStored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-0602HIGHStored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-4990HIGHStored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-4985HIGHStored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-4986HIGHStored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-4984HIGHStored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-4988HIGHStored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2025-4989HIGHStored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-4991HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-4983HIGHStored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2026-1284HIGHOut-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.3%CVE-2024-6380HIGHReflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2023-5597MEDIUMStored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2026-2101HIGHReflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19EPSS 0.3%