CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-7639

criticalcovered by 2 sourcesfirst seen 2026-08-13
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA >=2024|<=2024_SP1_P01 (CVE-2025-7639) Enterprise SCADA >=2023|<=2023_SP1 (CVE-2025-7639) Enterprise SCADA >=2022|<=2022_SP2_P2 (CVE-2025-7639) Enterprise SCADA <=2021_SP2_P5 (CVE-2025-7639) Enterprise SCADA HMI 2024|2024|R2 (CVE-2025-7639) Enterprise SCADA HMI <=2023_P1 (CVE-2025-7639) CVSS Vendor Equipment Vulnerabilities v3 7.1 AVEVA AVEVA Enterprise SCADA Deserialization of Untrusted Data Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2025-7639 The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps". View CVE Details Affected Products AVEVA Enterprise SCADA Vendor: AVEVA Product Version: AVEVA Enterprise SCADA: 2025, AVEVA Enterprise SCADA: >=2024|<=2024_SP1_P01, AVEVA Enterprise SCADA: >=2023|<=2023_SP1, AVEVA Enterprise SCADA: >=2022|<=2022_SP2_P2, AVEVA Enterprise SCADA: <=2021_SP2_P5, AVEVA Enterprise SCADA HMI: 2024|2024_R2, AVEVA Enterprise SCADA HMI: <=2023_P1 Product Status: known_affected Remediations Mitigation AVEVA recommends that customers using affected product versions should perform the following to mitigate the risk of exploit: 1. Evaluate the impact of these vulnerabilities based on your operational environment, architecture, and product implementation. 2. Plan an upgrade of Servers and Clients to one of the available fixed versions listed in this document. 3. Configure Servers and Clients as described

CSIRTS triage

vendor: AVEVAproduct: AVEVA Enterprise SCADAUnsafe deserializationRemote code executionaffected: <=2025, <=2024_SP1_P01, <=2023_SP1, <=2022_SP2_P2, <=2021_SP2_P5, 2024|2024|R2 HMI, <=2023_P1 HMI
What
Deserialization of untrusted data vulnerability allows attackers to tamper with serialized objects and execute arbitrary code during deserialization.
Who is affected
All versions of AVEVA Enterprise SCADA from 2021 through 2025 and HMI versions through 2024 in critical manufacturing worldwide.
Urgency
Immediate; critical severity with CVSS 7.1 and direct code execution capability via deserialization attack.
Action
Update AVEVA Enterprise SCADA and HMI to the latest patched versions released by AVEVA.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-7639

Get an email if CVE-2025-7639 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2025-7639

CVE.org record

Embed the live status

CVE-2025-7639 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-7639 status](https://www.csirts.com/badge/CVE-2025-7639)](https://www.csirts.com/cve/CVE-2025-7639)