The vulnerability, if exploited, could allow an authenticated miscreant
with "DNA Authority - Operator" privilege to tamper with serialized
data, potentially resulting in code execution during deserialization
under the privilege of Enterprise SCADA security group "DNA Apps".

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Security Updates Contact your AVEVA Technical Support representative, Customer Success Manager, Account Manager, or Solution Integrator to obtain the security update best applicable to the product version currently deployed in your environment: Servers: • AVEVA Enterprise SCADA v2025 P1 or higher • AVEVA Enterprise SCADA v2024 SP1 P2 • AVEVA Enterprise SCADA v2023 SP1 P1 • AVEVA Enterprise SCADA v2022 SP2 P3 • AVEVA Enterprise SCADA v2021 SP2 P6 • AVEVA Pipeline Operations for Gas/Liquids v2025 P1 or higher • AVEVA Pipeline Operations for Gas/Liquids v2024 SP1 P2 • AVEVA Pipeline Operations for Gas/Liquids v2023 SP1 P1 • AVEVA Pipeline Operations for Gas/Liquids v2022 SP2 P3 • AVEVA Pipeline Operations for Gas/Liquids v2021 SP2 P6 Clients: • AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher • AVEVA Enterprise SCADA HMI v2024 P1 • AVEVA Enterprise SCADA HMI v2023 P2 HF1 • AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher • AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher • Measurement Advisor 2025 P1 or higher • Measurement Advisor 2021 SP1 HF16


Workaround

Defensive Measures and General Considerations The following general defensive measures are recommended: - Audit devices, network topology, and perimeter defences to ensure all applicable security best practices from AVEVA’s Enterprise SCADA Reference System Architecture are adhered to. - Audit assigned permissions to ensure that only trusted users are given https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html - Disallow BLT Test clients in production environments. For additional details on defensive measures, please refer to Section 5 of KB117814 “AVEVA Midstream Product Bulletin – Removal of Binary Formatter” https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814 .

History

Fri, 14 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".
Title AVEVA Enterprise SCADA Deserialization of Untrusted Data
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-14T19:32:00.429Z

Reserved: 2025-07-14T14:27:04.249Z

Link: CVE-2025-7639

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T19:17:13.380

Modified: 2026-08-14T19:17:13.380

Link: CVE-2025-7639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses