CVE-2025-7639
AVEVA Enterprise SCADA Deserialization of Untrusted Data
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".
| CWE | CWE-502 |
| Vendor | aveva |
| Product | aveva enterprise scada |
| Published | Aug 14, 2026 |
| Last Updated | Aug 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for aveva aveva enterprise scada
Be the first to know when new unknown vulnerabilities affecting aveva aveva enterprise scada are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
AVEVA / AVEVA Enterprise SCADA
2025 2024 โค 2024 SP1 P01 2023 โค 2023 SP1 2022 โค 2022 SP2 P2 0 โค 2021 SP2 P5
AVEVA / AVEVA Enterprise SCADA HMI
2024 0 โค 2023_P1 2024 R2
AVEVA / AVEVA Pipeline Operations for Gas/Liquids
All versions affected AVEVA / AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media)
All versions affected AVEVA / AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media)
All versions affected AVEVA / Measurement Advisor
All versions affected References
aveva.com: https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json
Credits
AVEVA reported this vulnerability to CISA.