๐Ÿ” CVE Alert

CVE-2025-7639

UNKNOWN 0.0

AVEVA Enterprise SCADA Deserialization of Untrusted Data

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".

CWE CWE-502
Vendor aveva
Product aveva enterprise scada
Published Aug 14, 2026
Last Updated Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for aveva aveva enterprise scada

Be the first to know when new unknown vulnerabilities affecting aveva aveva enterprise scada are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

AVEVA / AVEVA Enterprise SCADA
2025 2024 โ‰ค 2024 SP1 P01 2023 โ‰ค 2023 SP1 2022 โ‰ค 2022 SP2 P2 0 โ‰ค 2021 SP2 P5
AVEVA / AVEVA Enterprise SCADA HMI
2024 0 โ‰ค 2023_P1 2024 R2
AVEVA / AVEVA Pipeline Operations for Gas/Liquids
All versions affected
AVEVA / AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media)
All versions affected
AVEVA / AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media)
All versions affected
AVEVA / Measurement Advisor
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
aveva.com: https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json

Credits

AVEVA reported this vulnerability to CISA.