3ds CVE Vulnerabilities & Metrics

Focus on 3ds vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About 3ds Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with 3ds. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total 3ds CVEs: 20
Earliest CVE date: 07 Sep 2012, 10:32 UTC
Latest CVE date: 02 Sep 2024, 12:15 UTC

Latest CVE reference: CVE-2024-8004

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 7

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -30.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -30.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical 3ds CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.64

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 17
4.0-6.9 2
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS 3ds CVEs

These are the five CVEs with the highest CVSS scores for 3ds, sorted by severity first and recency.

All CVEs for 3ds

CVE-2024-8004 3ds vulnerability CVSS: 0 02 Sep 2024, 12:15 UTC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-7939 3ds vulnerability CVSS: 0 02 Sep 2024, 12:15 UTC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-7938 3ds vulnerability CVSS: 0 02 Sep 2024, 12:15 UTC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-7932 3ds vulnerability CVSS: 0 02 Sep 2024, 12:15 UTC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-6379 3ds vulnerability CVSS: 0 20 Aug 2024, 14:15 UTC

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-6378 3ds vulnerability CVSS: 0 20 Aug 2024, 14:15 UTC

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-6377 3ds vulnerability CVSS: 0 20 Aug 2024, 14:15 UTC

An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.

CVE-2024-0935 3ds vulnerability CVSS: 0 01 Feb 2024, 14:15 UTC

Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024

CVE-2023-6078 3ds vulnerability CVSS: 0 01 Feb 2024, 14:15 UTC

An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.

CVE-2023-3589 3ds vulnerability CVSS: 0 09 Oct 2023, 09:15 UTC

A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.

CVE-2023-3588 3ds vulnerability CVSS: 0 13 Sep 2023, 19:15 UTC

A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code.

CVE-2023-1997 3ds vulnerability CVSS: 0 28 Aug 2023, 16:15 UTC

An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution.

CVE-2023-2763 3ds vulnerability CVSS: 0 12 Jul 2023, 08:15 UTC

Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF file.

CVE-2023-2762 3ds vulnerability CVSS: 0 12 Jul 2023, 08:15 UTC

A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.

CVE-2023-1996 3ds vulnerability CVSS: 0 19 May 2023, 17:15 UTC

A reflected Cross-site Scripting (XSS) vulnerability in Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023x allows an attacker to execute arbitrary script code.

CVE-2023-2141 3ds vulnerability CVSS: 0 21 Apr 2023, 16:15 UTC

An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

CVE-2023-2140 3ds vulnerability CVSS: 0 21 Apr 2023, 16:15 UTC

A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue requests to arbitrary hosts on behalf of the server running the DELMIA Apriso application.

CVE-2020-25507 3ds vulnerability CVSS: 7.2 28 Dec 2020, 20:15 UTC

An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arbitrary code as root. During installation, the user is instructed to set the system enviroment file with world writable permissions (0777 /etc/environment). Any local unprivileged user can execute arbitrary code simply by writing to /etc/environment, which will force all users, including root, to execute arbitrary code during the next login or reboot. In addition, the entire home directory of the twcloud user at /home/twcloud is recursively given world writable permissions. This allows any local unprivileged attacker to execute arbitrary code, as twcloud. This product was previous named Cameo Enterprise Data Warehouse (CEDW).

CVE-2014-2072 3ds vulnerability CVSS: 7.5 08 Jan 2020, 16:15 UTC

Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks

CVE-2014-2073 3ds vulnerability CVSS: 7.5 10 Apr 2018, 15:29 UTC

Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus."

CVE-2012-4883 3ds vulnerability CVSS: 6.9 07 Sep 2012, 10:32 UTC

Multiple untrusted search path vulnerabilities in 3DVIA Composer V6R2012 HF1 Build 6.8.1.1652 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) ibfs32.dll file in the current working directory, as demonstrated by a directory that contains a .smg file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2012-4882 3ds vulnerability CVSS: 6.9 07 Sep 2012, 10:32 UTC

Multiple untrusted search path vulnerabilities in 3D XML Player 6.212.13.12076 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) JT0DevPhase.dll file in the current working directory, as demonstrated by a directory that contains a .3dx file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.