An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
History

Tue, 21 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Dassault
Dassault station Launcher App
Vendors & Products Dassault
Dassault station Launcher App

Tue, 14 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Oct 2025 07:45:00 +0000

Type Values Removed Values Added
Description An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
Title OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published: 2025-10-13T07:33:15.695Z

Updated: 2025-10-14T13:15:34.207Z

Reserved: 2025-09-04T11:28:40.897Z

Link: CVE-2025-9976

cve-icon Vulnrichment

Updated: 2025-10-14T13:15:31.077Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-13T08:15:41.547

Modified: 2025-10-14T19:36:29.240

Link: CVE-2025-9976

cve-icon Redhat

No data.