CVE-2025-7639
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639) Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639) Enterprise SCADA >=2022|<=2022_SP2_P2 (CVE-2025-7639) Enterprise SCADA <=2021_SP2_P5 (CVE-2025-7639) Enterprise SCADA HMI 2024|2024|R2 (CVE-2025-7639) Enterprise SCADA HMI <=2023_P1 (CVE-2025-7639) CVSS Vendor Equipment Vulnerabilities v3 7.1 AVEVA AVEVA Enterprise SCADA Deserialization of Untrusted Data Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2025-7639 The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps". View CVE Details Affected Products AVEVA Enterprise SCADA Vendor: AVEVA Product Version: AVEVA Enterprise SCADA: 2025, AVEVA Enterprise SCADA: >=2024|<=2024_SP1_P01, AVEVA Enterprise SCADA: >=2023|<=2023_SP1, AVEVA Enterprise SCADA: >=2022|<=2022_SP2_P2, AVEVA Enterprise SCADA: <=2021_SP2_P5, AVEVA Enterprise SCADA HMI: 2024|2024_R2, AVEVA Enterprise SCADA HMI: <=2023_P1 Product Status: known_affected Remediations Mitigation AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described
CSIRTS triage
- What
- Deserialization of untrusted data vulnerability allows attackers to tamper with serialized objects and execute arbitrary code during deserialization.
- Who is affected
- All versions of AVEVA Enterprise SCADA from 2021 through 2025 and HMI versions through 2024 in critical manufacturing worldwide.
- Urgency
- Immediate; critical severity with CVSS 7.1 and direct code execution capability via deserialization attack.
- Action
- Update AVEVA Enterprise SCADA and HMI to the latest patched versions released by AVEVA.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2025-7639
Get an email if CVE-2025-7639 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownCVE-2025-7639: The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - O…nvd · 2026-08-14
- criticalAVEVA Enterprise SCADAcisa · 2026-08-13
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2025-7639)