CVE-2025-7639
Received Received - Intake

Authenticated Code Execution via Deserialization in Enterprise SCADA DNA Apps

Vulnerability report for CVE-2025-7639, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: ICS-CERT

Description

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
aveva enterprise_scada *
aveva pipeline_operations *
aveva enterprise_scada_hmi *
aveva pipeline_integrity_monitor *
aveva pipeline_training_simulator *
aveva measurement_advisor *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated attacker with 'DNA Authority - Operator' privileges to tamper with serialized data, potentially leading to arbitrary code execution during deserialization under the 'DNA Apps' security group.

Detection Guidance

Detection involves checking for unsafe deserialization practices and verifying serialization settings. Review server and client configurations to confirm binary serialization is disabled and JSON serialization is enforced. Audit user permissions for 'DNA Authority - Operator' privileges and inspect network traffic for unusual serialized data tampering attempts.

Impact Analysis

An attacker could exploit this to execute malicious code on systems running affected AVEVA Enterprise SCADA products, potentially leading to unauthorized access, data manipulation, or disruption of industrial control systems.

Mitigation Strategies

Immediately upgrade affected AVEVA Enterprise SCADA and related products to patched versions. Disable binary serialization and enforce JSON-only serialization on servers and clients. Audit and restrict 'DNA Authority - Operator' privileges. Contact AVEVA support for updates and follow KB117814 guidance. Disallow BLT Test clients in production environments and review network topology for unauthorized access points.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-7639. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart