Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Dassault Systèmes — Vulnerabilities & Security Advisories 107

Browse all 107 CVE security advisories affecting Dassault Systèmes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dassault Systèmes provides computer-aided design (CAD), computer-aided manufacturing (CAM), and product lifecycle management (PLM) software, primarily serving engineering and manufacturing sectors. The company’s extensive portfolio, including CATIA and SolidWorks, presents a significant attack surface, evidenced by the 95 recorded Common Vulnerabilities and Exposures (CVEs). Historically, these security flaws frequently involve remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities, often stemming from complex integrations and legacy codebases within its enterprise applications. While no single catastrophic breach has defined the vendor’s public security history, the high volume of CVEs indicates persistent challenges in patching and securing its diverse software ecosystem. Security analysts recommend rigorous network segmentation and immediate application of vendor patches to mitigate risks associated with these known exploits, particularly given the critical nature of the industrial data handled by its platforms.

CVE ID Title CVSS Severity Published
CVE-2024-1624 OS Command Injection vulnerability affecting documentation server on certain Releases of 3DEXPERIENCE, SIMULIA Abaqus, SIMULIA Isight and CATIA Composer — Documentation server CWE-78 9.4 Critical 2024-03-01
CVE-2024-1847 Multiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024 — eDrawings CWE-416 7.8 High 2024-02-28
CVE-2024-0935 Insertion of Sensitive Information into Log File vulnerabilities affecting DELMIA Apriso Release 2019 through Release 2024 — DELMIA Apriso CWE-532 4.4 Medium 2024-02-01
CVE-2023-6078 OS Command Injection vulnerability affecting BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023 — BIOVIA Materials Studio products CWE-78 8.8 High 2024-02-01
CVE-2023-5598 Stored Cross-site Scripting (XSS) vulnerabilities affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x — 3DSwymer CWE-79 5.4 Medium 2023-11-21
CVE-2023-5599 Stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x — 3DSwymer CWE-79 5.4 Medium 2023-11-21
CVE-2023-3589 Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x — Teamwork Cloud - Business Edition CWE-352 6.8 Medium 2023-10-09
CVE-2023-3588 Stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x — Teamwork Cloud - Business Edition CWE-79 5.4 Medium 2023-09-13
CVE-2023-1997 OS Command Injection vulnerability affecting SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x — SIMULIA 3DOrchestrate CWE-78 8.8 High 2023-08-28
CVE-2023-2763 Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023 — SOLIDWORKS Desktop CWE-416 7.8 High 2023-07-12
CVE-2023-2762 Use-After-Free vulnerability in SLDPRT file reading procedure affecting SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023 — SOLIDWORKS Desktop CWE-416 7.8 High 2023-07-12
CVE-2023-1996 Reflected Cross-site Scripting (XSS) vulnerability affecting Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023x — 3DEXPERIENCE CWE-79 6.1 Medium 2023-05-19
CVE-2023-2141 Unsafe .NET object deserialization affecting DELMIA Apriso Release 2017 through Release 2022 — DELMIA Apriso CWE-502 8.5 High 2023-04-21
CVE-2023-2140 Server-Side Request Forgery vulnerability affecting DELMIA Apriso Release 2017 through Release 2022 — DELMIA Apriso CWE-918 7.5 High 2023-04-21
CVE-2023-2139 Reflected Cross-site Scripting vulnerability affecting DELMIA Apriso Release 2017 through Release 2022 — DELMIA Apriso CWE-79 5.4 Medium 2023-04-21
CVE-2023-1288 ENOVIA Live Collaboration V6R2013xE is affected by an XML External Entity injection (XXE) vulnerability — ENOVIA Live Collaboration CWE-611 6.8 Medium 2023-03-09
CVE-2023-1287 ENOVIA Live Collaboration V6R2013xE is affected by an XSL template injection vulnerability — ENOVIA Live Collaboration CWE-74 9.0 Critical 2023-03-09

This page lists every published CVE security advisory associated with Dassault Systèmes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.