CVE-2023-2141 - CVE House
Back to Database
Status published High CVE-2023-2141

Unsafe .NET object deserialization affecting DELMIA Apriso Release 2017 through Release 2022

Vulnerability Description

An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2141

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mehdi Elyassa and Vincent Herbulot from Synacktiv

Affected Vendor

Dassault Systèmes

View all reports →

Affected Software

DELMIA Apriso
Vulnerable Versions:
Apriso 2017 Golden, Apriso 2018 Golden, Apriso 2019 Golden, Apriso 2020 Golden, Apriso 2021 Golden, Apriso 2022 Golden

Timeline

Official Publish: April 21st, 2023
Last Modified: February 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)