As cited
Copy frozen at (site build).
ot ics
AVEVA Enterprise SCADA
AVEVA Enterprise SCADA versions spanning 2021 through 2025 contain a deserialization vulnerability (CVE-2025-7639) that could allow authenticated attackers with operator privileges to execute code under the security context of the DNA Apps group. AVEVA has published patched versions and released configuration guidance to disable binary formatter usage in favor of JSON serialization. The vulnerability carries a CVSS base score of 7.1 and affects critical infrastructure deployments worldwide.
Why it matters: Industrial control system operators and asset owners running any AVEVA Enterprise SCADA version between 2021 and 2025 must apply the recommended patches and configuration changes immediately, as this permits code execution by authenticated insiders with operator rights in critical manufacturing environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ot ics
AVEVA Enterprise SCADA
AVEVA Enterprise SCADA versions spanning 2021 through 2025 contain a deserialization vulnerability (CVE-2025-7639) that could allow authenticated attackers with operator privileges to execute code under the security context of the DNA Apps group. AVEVA has published patched versions and released configuration guidance to disable binary formatter usage in favor of JSON serialization. The vulnerability carries a CVSS base score of 7.1 and affects critical infrastructure deployments worldwide.
Why it matters: Industrial control system operators and asset owners running any AVEVA Enterprise SCADA version between 2021 and 2025 must apply the recommended patches and configuration changes immediately, as this permits code execution by authenticated insiders with operator rights in critical manufacturing environments.
- Source published
- First seen by Cybersecurity Tracker