CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

AVEVA Enterprise SCADA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4398

As cited

Copy frozen at (site build).

ot ics

AVEVA Enterprise SCADA

AVEVA Enterprise SCADA versions spanning 2021 through 2025 contain a deserialization vulnerability (CVE-2025-7639) that could allow authenticated attackers with operator privileges to execute code under the security context of the DNA Apps group. AVEVA has published patched versions and released configuration guidance to disable binary formatter usage in favor of JSON serialization. The vulnerability carries a CVSS base score of 7.1 and affects critical infrastructure deployments worldwide.

Why it matters: Industrial control system operators and asset owners running any AVEVA Enterprise SCADA version between 2021 and 2025 must apply the recommended patches and configuration changes immediately, as this permits code execution by authenticated insiders with operator rights in critical manufacturing environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ot ics

AVEVA Enterprise SCADA

AVEVA Enterprise SCADA versions spanning 2021 through 2025 contain a deserialization vulnerability (CVE-2025-7639) that could allow authenticated attackers with operator privileges to execute code under the security context of the DNA Apps group. AVEVA has published patched versions and released configuration guidance to disable binary formatter usage in favor of JSON serialization. The vulnerability carries a CVSS base score of 7.1 and affects critical infrastructure deployments worldwide.

Why it matters: Industrial control system operators and asset owners running any AVEVA Enterprise SCADA version between 2021 and 2025 must apply the recommended patches and configuration changes immediately, as this permits code execution by authenticated insiders with operator rights in critical manufacturing environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary