CVE-2024-1624: 3ds 3dexperience

Critical severity, CVSS 9.4. EPSS: 2.1% chance of exploitation in the next 30 days.

An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA Composer from Release R2023 through Release R2024. A specially crafted HTTP request can lead to arbitrary command execution.

Affected products

  • 3ds 3dexperience: from r2022x_golden, up to and including r2022.fp.cfa.2406; from r2023x_golden, up to and including R2023x.FP.CFA.2350; from r2024x_golden, up to and including R2024x.FP.CFA.2405
  • 3ds Catia Composer: from r2023_golden, up to and including R2023_Refresh4; from r2024_golden, up to and including R2023_Refresh3
  • 3ds Simulia Abaqus: from 2022_golden, up to and including 2022.FP.CFA.2406; from 2023_golden, up to and including 2023.FP.CFA.2350; from 2024_golden, up to and including 2024.FP.CFA.2405
  • 3ds Simulia Insight: version 2022_golden only; version 2023_golden only; version 2024_golden only
  • Dassault Systèmes Documentation Server: from 3DEXPERIENCE R2022x Golden, up to and including 3DEXPERIENCE R2022x.FP.CFA.2406; from 3DEXPERIENCE R2023x Golden, up to and including 3DEXPERIENCE R2023x FP.CFA.2350; from 3DEXPERIENCE R2024x Golden, up to and including 3DEXPERIENCE R2024x.FP.CFA.2405

Published 2024-03-01. Last modified 2026-06-17.