{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-7639",
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"state": "PUBLISHED",
"assignerShortName": "icscert",
"dateReserved": "2025-07-14T14:27:04.249Z",
"datePublished": "2026-08-14T18:46:18.583Z",
"dateUpdated": "2026-08-17T20:01:29.491Z"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert",
"dateUpdated": "2026-08-17T14:33:36.590Z"
},
"title": "AVEVA Enterprise SCADA Deserialization of Untrusted Data",
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"cweId": "CWE-502",
"description": "CWE-502",
"type": "CWE"
}
]
}
],
"affected": [
{
"vendor": "AVEVA",
"product": "AVEVA Enterprise SCADA",
"versions": [
{
"status": "affected",
"version": "2025"
},
{
"status": "affected",
"version": "2024",
"lessThanOrEqual": "2024 SP1 P01",
"versionType": "custom"
},
{
"status": "affected",
"version": "2023",
"lessThanOrEqual": "2023 SP1",
"versionType": "custom"
},
{
"status": "affected",
"version": "2022",
"lessThanOrEqual": "2022 SP2 P2",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThanOrEqual": "2021 SP2 P5",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "2025 P1"
},
{
"status": "unaffected",
"version": "2024 SP1 P2"
},
{
"status": "unaffected",
"version": "2023 SP1 P1"
},
{
"status": "unaffected",
"version": "2022 SP2 P3"
},
{
"status": "unaffected",
"version": "2021 SP2 P6"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "AVEVA",
"product": "AVEVA Enterprise SCADA HMI",
"versions": [
{
"status": "affected",
"version": "2024"
},
{
"status": "affected",
"version": "0",
"lessThanOrEqual": "2023_P1",
"versionType": "custom"
},
{
"status": "affected",
"version": "2024 R2"
},
{
"status": "unaffected",
"version": "2024 R2 HF7"
},
{
"status": "unaffected",
"version": "2024 P1"
},
{
"status": "unaffected",
"version": "2023 P2 HF1"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "AVEVA",
"product": "AVEVA Pipeline Operations for Gas/Liquids",
"versions": [
{
"status": "unaffected",
"version": "2025 P1"
},
{
"status": "unaffected",
"version": "2024 SP1 P2"
},
{
"status": "unaffected",
"version": "2023 SP1 P1"
},
{
"status": "unaffected",
"version": "2022 SP2 P3"
},
{
"status": "unaffected",
"version": "2021 SP2 P6"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "AVEVA",
"product": "AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media)",
"versions": [
{
"status": "unaffected",
"version": "2025 SP1 P2"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "AVEVA",
"product": "AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media)",
"versions": [
{
"status": "unaffected",
"version": "2025 SP1 P2"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "AVEVA",
"product": "Measurement Advisor",
"versions": [
{
"status": "unaffected",
"version": "2025 P1"
},
{
"status": "unaffected",
"version": "2021 SP1 HF16"
}
],
"defaultStatus": "unaffected"
}
],
"descriptions": [
{
"lang": "en",
"value": "The vulnerability, if exploited, could allow an authenticated miscreant \nwith \"DNA Authority - Operator\" privilege to tamper with serialized \ndata, potentially resulting in code execution during deserialization \nunder the privilege of Enterprise SCADA security group \"DNA Apps\".",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "The vulnerability, if exploited, could allow an authenticated miscreant \nwith \"DNA Authority - Operator\" privilege to tamper with serialized \ndata, potentially resulting in code execution during deserialization \nunder the privilege of Enterprise SCADA security group \"DNA Apps\"."
}
]
}
],
"references": [
{
"url": "https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV4_0": {
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "LOW",
"subConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"version": "4.0",
"baseSeverity": "MEDIUM",
"baseScore": 6.1,
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
}
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseSeverity": "HIGH",
"baseScore": 7.1,
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H"
}
}
],
"workarounds": [
{
"lang": "en",
"value": "Defensive Measures and General Considerations\nThe following general defensive measures are recommended:\n- Audit devices, network topology, and perimeter defences to ensure all applicable security best practices from AVEVA’s Enterprise SCADA Reference System Architecture are adhered to.\n- Audit assigned permissions to ensure that only trusted users are given https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html \n- Disallow BLT Test clients in production environments.\nFor additional details on defensive measures, please refer to Section 5 of KB117814 “AVEVA Midstream Product Bulletin – Removal of Binary Formatter” https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814 .",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Defensive Measures and General Considerations
The following general defensive measures are recommended:
- Audit devices, network topology, and perimeter defences to ensure all applicable security best practices from AVEVA’s Enterprise SCADA Reference System Architecture are adhered to.
- Audit assigned permissions to ensure that only trusted users are given “DNA Authority – Operator” rights: https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html
- Disallow BLT Test clients in production environments.
For additional details on defensive measures, please refer to Section 5 of KB117814 “AVEVA Midstream Product Bulletin – Removal of Binary Formatter”."
}
]
}
],
"solutions": [
{
"lang": "en",
"value": "Security Updates\n\nContact your AVEVA Technical Support representative, Customer Success Manager, Account Manager, or Solution Integrator to obtain the security update best applicable to the product version currently deployed in your environment:\n\nServers:\n• AVEVA Enterprise SCADA v2025 P1 or higher\n• AVEVA Enterprise SCADA v2024 SP1 P2\n• AVEVA Enterprise SCADA v2023 SP1 P1\n• AVEVA Enterprise SCADA v2022 SP2 P3\n• AVEVA Enterprise SCADA v2021 SP2 P6\n• AVEVA Pipeline Operations for Gas/Liquids v2025 P1 or higher\n• AVEVA Pipeline Operations for Gas/Liquids v2024 SP1 P2\n• AVEVA Pipeline Operations for Gas/Liquids v2023 SP1 P1\n• AVEVA Pipeline Operations for Gas/Liquids v2022 SP2 P3\n• AVEVA Pipeline Operations for Gas/Liquids v2021 SP2 P6\n\n\n\n\nClients:\n• AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher\n• AVEVA Enterprise SCADA HMI v2024 P1\n• AVEVA Enterprise SCADA HMI v2023 P2 HF1\n• AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher\n• AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher\n• Measurement Advisor 2025 P1 or higher\n• Measurement Advisor 2021 SP1 HF16",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "