Status: UPDATED | Advisory ID: CVE-2025-7639
| CVE | CVE-2025-7639 |
| CVSS Score / Version | 7.1 (High) / CVSS v3.1 |
| Updated | 2026-09-29 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is high; availability impact is high. |
| Affected products | AVEVA Enterprise SCADA and AVEVA Enterprise SCADA HMI |
| Classified as | CWE-502 (Deserialization of Untrusted Data) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| AVEVA | AVEVA Enterprise SCADA | ||
| AVEVA | AVEVA Enterprise SCADA HMI |
| Subsystems | General OT |
| Sectors | Multiple |
The vulnerability, if exploited, could allow an authenticated miscreant
with "DNA Authority - Operator" privilege to tamper with serialized
data, potentially resulting in code execution during deserialization
under the privilege of Enterprise SCADA security group "DNA Apps".
Monitor AVEVA's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2025-7639 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2025-7639 |