Deserialization Vulnerability in AVEVA's DNA Apps
CVE-2025-7639

10CRITICAL

What is CVE-2025-7639?

An authenticated attacker with 'DNA Authority - Operator' privileges may exploit this vulnerability to tamper with serialized data. This manipulation can lead to code execution during deserialization under the authority of the Enterprise SCADA security group, potentially jeopardizing the integrity and security of affected systems.

Affected Version(s)

AVEVA Enterprise SCADA 2025

AVEVA Enterprise SCADA 2024 <= 2024 SP1 P01

AVEVA Enterprise SCADA 2023 <= 2023 SP1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AVEVA reported this vulnerability to CISA.
.