Vulnerabilidades en Dassault Systèmes

106 resultados
Análisis Vexday

O portfólio da Dassault Systèmes acumula 98 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa que está 6,8 vezes acima da média geral do catálogo, sinalizando risco operacional elevado para ambientes que utilizam essas soluções. A CVE mais crítica no momento, CVE-2025-5086, apresenta EPSS de 0,89, indicando probabilidade muito alta de exploração iminente e demandando atenção prioritária de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere lacunas persistentes em validação de entrada e saída nas aplicações do vendor. Com 8 CVEs de severidade crítica e 6 surgidas nos últimos 90 dias, a superfície de ataque permanece ativa e requer monitoramento contínuo.

CVE-2024-6377HIGHURL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2024-6380HIGHReflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2025-10559HIGHPath Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2024-1848HIGHMultiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024EPSS 0.3%CVE-2026-2101HIGHReflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19EPSS 0.3%CVE-2026-16279CRITICALImproper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026xEPSS 0.3%CVE-2023-5597MEDIUMStored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024xEPSS 0.3%CVE-2025-0600HIGHStored Cross-site Scripting (XSS) vulnerability affecting Product Explorer in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0830HIGHStored Cross-site Scripting (XSS) vulnerability affecting Meeting Management in ENOVIA Change Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0832HIGHStored Cross-site Scripting (XSS) vulnerability affecting Project Gantt in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0599HIGHStored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0598HIGHStored Cross-site Scripting (XSS) vulnerability affecting Relations in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0833HIGHStored Cross-site Scripting (XSS) vulnerability affecting Route Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0596HIGHStored Cross-site Scripting (XSS) vulnerability affecting Bookmark Editor in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0829HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0828HIGHStored Cross-site Scripting (XSS) vulnerability affecting Engineering Release in ENOVIA Product Engineering Specialist from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0601HIGHStored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-0826HIGHStored Cross-site Scripting (XSS) vulnerability affecting 3D Navigate in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%CVE-2025-10555HIGHStored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025xEPSS 0.2%CVE-2024-6379HIGHReflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024xEPSS 0.2%