with "DNA Authority - Operator" privilege to tamper with serialized
data, potentially resulting in code execution during deserialization
under the privilege of Enterprise SCADA security group "DNA Apps".
Project Subscriptions
No data.
No advisories yet.
Solution
Security Updates Contact your AVEVA Technical Support representative, Customer Success Manager, Account Manager, or Solution Integrator to obtain the security update best applicable to the product version currently deployed in your environment: Servers: • AVEVA Enterprise SCADA v2025 P1 or higher • AVEVA Enterprise SCADA v2024 SP1 P2 • AVEVA Enterprise SCADA v2023 SP1 P1 • AVEVA Enterprise SCADA v2022 SP2 P3 • AVEVA Enterprise SCADA v2021 SP2 P6 • AVEVA Pipeline Operations for Gas/Liquids v2025 P1 or higher • AVEVA Pipeline Operations for Gas/Liquids v2024 SP1 P2 • AVEVA Pipeline Operations for Gas/Liquids v2023 SP1 P1 • AVEVA Pipeline Operations for Gas/Liquids v2022 SP2 P3 • AVEVA Pipeline Operations for Gas/Liquids v2021 SP2 P6 Clients: • AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher • AVEVA Enterprise SCADA HMI v2024 P1 • AVEVA Enterprise SCADA HMI v2023 P2 HF1 • AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher • AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher • Measurement Advisor 2025 P1 or higher • Measurement Advisor 2021 SP1 HF16
Workaround
Defensive Measures and General Considerations The following general defensive measures are recommended: - Audit devices, network topology, and perimeter defences to ensure all applicable security best practices from AVEVA’s Enterprise SCADA Reference System Architecture are adhered to. - Audit assigned permissions to ensure that only trusted users are given https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html - Disallow BLT Test clients in production environments. For additional details on defensive measures, please refer to Section 5 of KB117814 “AVEVA Midstream Product Bulletin – Removal of Binary Formatter” https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814 .
Fri, 14 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps". | |
| Title | AVEVA Enterprise SCADA Deserialization of Untrusted Data | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-14T19:32:00.429Z
Reserved: 2025-07-14T14:27:04.249Z
Link: CVE-2025-7639
No data.
Status : Received
Published: 2026-08-14T19:17:13.380
Modified: 2026-08-14T19:17:13.380
Link: CVE-2025-7639
No data.
OpenCVE Enrichment
No data.