AVEVA Enterprise SCADA
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639) Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639) Enterprise SCADA >=2022|<=2022_SP2_P2 (CVE-2025-7639) Enterprise SCADA <=2021_SP2_P5 (CVE-2025-7639) Enterprise SCADA HMI 2024|2024|R2 (CVE-2025-7639) Enterprise SCADA HMI <=2023_P1 (CVE-2025-7639) CVSS Vendor Equipment Vulnerabilities v3 7.1 AVEVA AVEVA Enterprise SCADA Deserialization of Untrusted Data Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2025-7639 The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps". View CVE Details Affected Products AVEVA Enterprise SCADA Vendor: AVEVA Product Version: AVEVA Enterprise SCADA: 2025, AVEVA Enterprise SCADA: >=2024|<=2024_SP1_P01, AVEVA Enterprise SCADA: >=2023|<=2023_SP1, AVEVA Enterprise SCADA: >=2022|<=2022_SP2_P2, AVEVA Enterprise SCADA: <=2021_SP2_P5, AVEVA Enterprise SCADA HMI: 2024|2024_R2, AVEVA Enterprise SCADA HMI: <=2023_P1 Product Status: known_affected Remediations Mitigation AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described
CSIRTS triage
- What
- Deserialization of untrusted data vulnerability allows attackers to tamper with serialized objects and execute arbitrary code during deserialization.
- Who is affected
- All versions of AVEVA Enterprise SCADA from 2021 through 2025 and HMI versions through 2024 in critical manufacturing worldwide.
- Urgency
- Immediate; critical severity with CVSS 7.1 and direct code execution capability via deserialization attack.
- Action
- Update AVEVA Enterprise SCADA and HMI to the latest patched versions released by AVEVA.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch AVEVA Enterprise SCADA
Get an email when a new AVEVA Enterprise SCADA advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-76390.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-7639 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CISA Cybersecurity Advisories
- criticalANDRITZ HIPASE-250 and 250 SCALA2026-08-13
- criticalSiemens Simcenter Femap2026-08-13
- criticalSiemens License Server (SLS)2026-08-13
- criticalSiemens Parasolid2026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13