← All Advisories

CVE-2025-7639

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2025-7639

Key Details

CVECVE-2025-7639
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-29
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is high; availability impact is high.
Affected productsAVEVA Enterprise SCADA and AVEVA Enterprise SCADA HMI
Classified asCWE-502 (Deserialization of Untrusted Data)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
AVEVAAVEVA Enterprise SCADA
AVEVAAVEVA Enterprise SCADA HMI
SubsystemsGeneral OT
SectorsMultiple

What to Know

The vulnerability, if exploited, could allow an authenticated miscreant

with "DNA Authority - Operator" privilege to tamper with serialized

data, potentially resulting in code execution during deserialization

under the privilege of Enterprise SCADA security group "DNA Apps".

What to Do

Monitor AVEVA's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-7639
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-7639