CVE-2025-7639: AVEVA Enterprise SCADA Deserialization of Untrusted Data
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVEVA Enterprise SCADA HMIto a version that resolves this vulnerability.Fixed in v2023 P2 HF1 - Upgrade
Upgrade
AVEVA Enterprise SCADA HMIto a version that resolves this vulnerability.Fixed in v2024 P1 - Upgrade
Upgrade
AVEVA Enterprise SCADA HMIto a version that resolves this vulnerability.Fixed in v2024 R2 HF7 - Upgrade
Upgrade
AVEVA Enterprise SCADAto a version that resolves this vulnerability.Fixed in v2021 SP2 P6 - Upgrade
Upgrade
AVEVA Enterprise SCADAto a version that resolves this vulnerability.Fixed in v2022 SP2 P3 - Upgrade
Upgrade
AVEVA Enterprise SCADAto a version that resolves this vulnerability.Fixed in v2023 SP1 P1 - Upgrade
Upgrade
AVEVA Enterprise SCADAto a version that resolves this vulnerability.Fixed in v2024 SP1 P2 - Upgrade
Upgrade
AVEVA Enterprise SCADAto a version that resolves this vulnerability.Fixed in v2025 P1 - Upgrade
Upgrade
AVEVA Pipeline Integrity Monitorto a version that resolves this vulnerability.Fixed in v2025 SP1 P2 - Upgrade
Upgrade
AVEVA Pipeline Operations for Gas/Liquidsto a version that resolves this vulnerability.Fixed in v2021 SP2 P6 - Upgrade
Upgrade
AVEVA Pipeline Operations for Gas/Liquidsto a version that resolves this vulnerability.Fixed in v2022 SP2 P3 - Upgrade
Upgrade
AVEVA Pipeline Operations for Gas/Liquidsto a version that resolves this vulnerability.Fixed in v2023 SP1 P1 - Upgrade
Upgrade
AVEVA Pipeline Operations for Gas/Liquidsto a version that resolves this vulnerability.Fixed in v2024 SP1 P2 - Upgrade
Upgrade
AVEVA Pipeline Operations for Gas/Liquidsto a version that resolves this vulnerability.Fixed in v2025 P1 - Upgrade
Upgrade
AVEVA Pipeline Training Simulatorto a version that resolves this vulnerability.Fixed in v2025 SP1 P2 - Upgrade
Upgrade
AVEVA Measurement Advisorto a version that resolves this vulnerability.Fixed in v2025 P1 - Configuration
Change the Enterprise SCADA 'BinarySerializer' setting 'AcceptBinaryFormattedData' from 'true' to 'false' as part of applying secure serialization settings.
AVEVA Enterprise SCADA HMI / Enterprise SCADA configuration BinarySerializer -> AcceptBinaryFormattedData = false - Configuration
Change the Enterprise SCADA 'BinarySerializer' setting 'Mode' from 'Binary Formatter' to 'Json'.
AVEVA Enterprise SCADA HMI / Enterprise SCADA configuration BinarySerializer -> Mode = Json - Configuration
Configure Enterprise SCADA clients/products that interface with Enterprise SCADA to only use JSON serialization.
AVEVA Enterprise SCADA client interfaces Serialization format = JSON - Compensating control
For fully mitigating risk of exploit, implement the required configuration changes after all server and client nodes have been upgraded to compatible versions that support the fix.
- Operational
Re-cache the XOS Event Handlers assembly after applying the secure serialization settings and the required upgrades.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7639?
CVE-2025-7639 has a risk score of 53, indicating a moderate severity level.
How do I fix CVE-2025-7639?
To remediate CVE-2025-7639, update your AVEVA Enterprise SCADA to the latest version provided by the vendor.
Who is affected by CVE-2025-7639?
CVE-2025-7639 affects users with 'DNA Authority - Operator' privileges in AVEVA Enterprise SCADA systems.
What can happen if CVE-2025-7639 is exploited?
If exploited, CVE-2025-7639 could allow an attacker to tamper with serialized data, potentially leading to code execution.
When was CVE-2025-7639 published?
CVE-2025-7639 was published on August 14, 2026.