AllCyberNews

CVE-2025-7639

AVEVA Enterprise SCADA Deserialization of Untrusted Data

CVSS 6.1 medium · AVEVA AVEVA Enterprise SCADA · published 2026-08-14

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".

Coverage 1 source

  1. 2026-08-13 CISA Cybersecurity Advisories high AVEVA Enterprise SCADA

    AVEVA Enterprise SCADA has a vulnerability allowing potential code execution during deserialization.

Also covered