CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

AVEVA Enterprise SCADA

criticalCVE-2025-7639
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639) Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639) Enterprise SCADA >=2022|<=2022_SP2_P2 (CVE-2025-7639) Enterprise SCADA <=2021_SP2_P5 (CVE-2025-7639) Enterprise SCADA HMI 2024|2024|R2 (CVE-2025-7639) Enterprise SCADA HMI <=2023_P1 (CVE-2025-7639) CVSS Vendor Equipment Vulnerabilities v3 7.1 AVEVA AVEVA Enterprise SCADA Deserialization of Untrusted Data Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2025-7639 The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps". View CVE Details Affected Products AVEVA Enterprise SCADA Vendor: AVEVA Product Version: AVEVA Enterprise SCADA: 2025, AVEVA Enterprise SCADA: >=2024|<=2024_SP1_P01, AVEVA Enterprise SCADA: >=2023|<=2023_SP1, AVEVA Enterprise SCADA: >=2022|<=2022_SP2_P2, AVEVA Enterprise SCADA: <=2021_SP2_P5, AVEVA Enterprise SCADA HMI: 2024|2024_R2, AVEVA Enterprise SCADA HMI: <=2023_P1 Product Status: known_affected Remediations Mitigation AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described

CSIRTS triage

vendor: AVEVAproduct: AVEVA Enterprise SCADAUnsafe deserializationRemote code executionaffected: <=2025, <=2024_SP1_P01, <=2023_SP1, <=2022_SP2_P2, <=2021_SP2_P5, 2024|2024|R2 HMI, <=2023_P1 HMI
What
Deserialization of untrusted data vulnerability allows attackers to tamper with serialized objects and execute arbitrary code during deserialization.
Who is affected
All versions of AVEVA Enterprise SCADA from 2021 through 2025 and HMI versions through 2024 in critical manufacturing worldwide.
Urgency
Immediate; critical severity with CVSS 7.1 and direct code execution capability via deserialization attack.
Action
Update AVEVA Enterprise SCADA and HMI to the latest patched versions released by AVEVA.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch AVEVA Enterprise SCADA

Get an email when a new AVEVA Enterprise SCADA advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-13
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-7639coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories