CVE-2025-7639: AVEVA Enterprise SCADA Deserialization of Untrusted Data

Published Aug 14, 2026
·
Updated

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".

Affected Software

1 affected component
AVEVA Enterprise SCADA

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade AVEVA Enterprise SCADA HMI to a version that resolves this vulnerability.

    Fixed in v2023 P2 HF1
  2. Upgrade

    Upgrade AVEVA Enterprise SCADA HMI to a version that resolves this vulnerability.

    Fixed in v2024 P1
  3. Upgrade

    Upgrade AVEVA Enterprise SCADA HMI to a version that resolves this vulnerability.

    Fixed in v2024 R2 HF7
  4. Upgrade

    Upgrade AVEVA Enterprise SCADA to a version that resolves this vulnerability.

    Fixed in v2021 SP2 P6
  5. Upgrade

    Upgrade AVEVA Enterprise SCADA to a version that resolves this vulnerability.

    Fixed in v2022 SP2 P3
  6. Upgrade

    Upgrade AVEVA Enterprise SCADA to a version that resolves this vulnerability.

    Fixed in v2023 SP1 P1
  7. Upgrade

    Upgrade AVEVA Enterprise SCADA to a version that resolves this vulnerability.

    Fixed in v2024 SP1 P2
  8. Upgrade

    Upgrade AVEVA Enterprise SCADA to a version that resolves this vulnerability.

    Fixed in v2025 P1
  9. Upgrade

    Upgrade AVEVA Pipeline Integrity Monitor to a version that resolves this vulnerability.

    Fixed in v2025 SP1 P2
  10. Upgrade

    Upgrade AVEVA Pipeline Operations for Gas/Liquids to a version that resolves this vulnerability.

    Fixed in v2021 SP2 P6
  11. Upgrade

    Upgrade AVEVA Pipeline Operations for Gas/Liquids to a version that resolves this vulnerability.

    Fixed in v2022 SP2 P3
  12. Upgrade

    Upgrade AVEVA Pipeline Operations for Gas/Liquids to a version that resolves this vulnerability.

    Fixed in v2023 SP1 P1
  13. Upgrade

    Upgrade AVEVA Pipeline Operations for Gas/Liquids to a version that resolves this vulnerability.

    Fixed in v2024 SP1 P2
  14. Upgrade

    Upgrade AVEVA Pipeline Operations for Gas/Liquids to a version that resolves this vulnerability.

    Fixed in v2025 P1
  15. Upgrade

    Upgrade AVEVA Pipeline Training Simulator to a version that resolves this vulnerability.

    Fixed in v2025 SP1 P2
  16. Upgrade

    Upgrade AVEVA Measurement Advisor to a version that resolves this vulnerability.

    Fixed in v2025 P1
  17. Configuration

    Change the Enterprise SCADA 'BinarySerializer' setting 'AcceptBinaryFormattedData' from 'true' to 'false' as part of applying secure serialization settings.

    AVEVA Enterprise SCADA HMI / Enterprise SCADA configuration BinarySerializer -> AcceptBinaryFormattedData = false
  18. Configuration

    Change the Enterprise SCADA 'BinarySerializer' setting 'Mode' from 'Binary Formatter' to 'Json'.

    AVEVA Enterprise SCADA HMI / Enterprise SCADA configuration BinarySerializer -> Mode = Json
  19. Configuration

    Configure Enterprise SCADA clients/products that interface with Enterprise SCADA to only use JSON serialization.

    AVEVA Enterprise SCADA client interfaces Serialization format = JSON
  20. Compensating control

    For fully mitigating risk of exploit, implement the required configuration changes after all server and client nodes have been upgraded to compatible versions that support the fix.

  21. Operational

    Re-cache the XOS Event Handlers assembly after applying the secure serialization settings and the required upgrades.

Event History

Aug 14, 2026
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
RemedyDescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-7639?

CVE-2025-7639 has a risk score of 53, indicating a moderate severity level.

2

How do I fix CVE-2025-7639?

To remediate CVE-2025-7639, update your AVEVA Enterprise SCADA to the latest version provided by the vendor.

3

Who is affected by CVE-2025-7639?

CVE-2025-7639 affects users with 'DNA Authority - Operator' privileges in AVEVA Enterprise SCADA systems.

4

What can happen if CVE-2025-7639 is exploited?

If exploited, CVE-2025-7639 could allow an attacker to tamper with serialized data, potentially leading to code execution.

5

When was CVE-2025-7639 published?

CVE-2025-7639 was published on August 14, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203