« Volver al listado

CVE-2025-10559

Estado: AnalizadaCrítica (9.1)—

A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to read or write files in specific directories on the server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota sin autenticación (AV:N, PR:N) en aplicación expuesta. Path traversal (CWE-22) permite lectura (C:H) y escritura (I:H) de archivos en el servidor.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-10559",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-10559",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-31T15:03:55.267937Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "3DS.Information-Security@3ds.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "3DS.Information-Security@3ds.com",
      "affectedData": [
        {
          "vendor": "Dassault Systèmes",
          "product": "DELMIA Factory Resource Manager",
          "versions": [
            {
              "status": "affected",
              "version": "Release 3DEXPERIENCE R2023x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "Release 3DEXPERIENCE R2023x.FP.CFA.2541"
            },
            {
              "status": "affected",
              "version": "Release 3DEXPERIENCE R2024x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "Release 3DEXPERIENCE R2024x.FP.CFA.2537"
            },
            {
              "status": "affected",
              "version": "Release 3DEXPERIENCE R2025x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "Release 3DEXPERIENCE R2025x.FP.CFA.2514"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-31T09:16:21.970",
  "references": [
    {
      "url": "https://www.3ds.com/trust-center/security/security-advisories/cve-2025-10559",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "3DS.Information-Security@3ds.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "3DS.Information-Security@3ds.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to read or write files in specific directories on the server."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de salto de ruta que afecta a la Gestión de Recursos de Fábrica en DELMIA Factory Resource Manager desde la versión 3DEXPERIENCE R2023x hasta la versión 3DEXPERIENCE R2025x permite a un atacante leer o escribir archivos en directorios específicos en el servidor."
    }
  ],
  "lastModified": "2026-06-17T08:28:31.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:3ds:3dexperience:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D800681-01F0-43E4-9525-BE188167D292",
              "versionEndIncluding": "r2025x",
              "versionStartIncluding": "r2023x"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "3DS.Information-Security@3ds.com"
}