CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-10557: 3dexperience enovia from r2023x (inclusive), through r2025x (inclusive); +1 more affected products

CVE-2025-10557. CVSS 3.1 base score 5.4 (MEDIUM, NVD). EPSS 0.00201 (percentile 0.09119), scored 2026-10-06.

Affected technology

3dexperience enovia · from r2023x (inclusive), through r2025x (inclusive)
3ds

ENOVIA Collaborative Industry Innovator · Release 3DEXPERIENCE R2022x Golden through Release 3DEXPERIENCE R2022x.FP.CFA.2513, Release 3DEXPERIENCE R2023x Golden through Release 3DEXPERIENCE R2023x.FP.CFA.2514, Release 3DEXPERIENCE R2024x Golden through Release 3DEXPERIENCE R2024x.FP.CFA.2510, Release 3DEXPERIENCE R2025x Golden through Release 3DEXPERIENCE R2024x.FP.CFA.2514
Dassault Systèmes

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · User interaction required

Attack conditions (NVD, CVSS 3.1): Network (remote) · Low privileges required · User interaction required

What an attacker can do

An attacker can execute arbitrary script code in user's browser session. Vendor/CNA’s CVSS 3.1 assessment (base score 8.7/10) rates confidentiality and integrity impact as high; availability impact as none. NVD’s CVSS 3.1 assessment (base score 5.4/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-79
CCR priority
21.7 /100 (P4)
CVSS 3.1
5.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N · NVD
EPSS
0.00201 · percentile 0.09162 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-10557.html