← Back to Feed
AVEVA Enterprise SCADA
CVE-2025-7639
August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL
AVEVA Enterprise SCADA contains a deserialization of untrusted data vulnerability in multiple versions from 2021 through 2025 and HMI releases. An authenticated Operator can tamper with serialized data, potentially causing code execution as DNA Apps during deserialization. AVEVA advises upgrading to available fixed versions after evaluating operational impact.
Key Takeaways
- Authenticated attackers with DNA Authority - Operator privilege can tamper with serialized data in AVEVA Enterprise SCADA.
- Exploitation can lead to code execution during deserialization under the Enterprise SCADA DNA Apps security group.
- Affects SCADA 2021 through 2025, HMI 2024 R2 and earlier; AVEVA recommends upgrading to fixed versions.