VYPR
advisoryPublished Aug 13, 2026· 1 source

CISA Warns of Deserialization Vulnerability in AVEVA Enterprise SCADA

A critical deserialization vulnerability (CVE-2025-7639) in AVEVA Enterprise SCADA could allow authenticated attackers to execute code, impacting critical manufacturing sectors.

CISA has issued a security advisory detailing a critical deserialization vulnerability, identified as CVE-2025-7639, affecting multiple versions of AVEVA Enterprise SCADA. This vulnerability poses a significant risk to industrial control systems, particularly within the critical manufacturing sector, with worldwide deployment.

The vulnerability stems from the deserialization of untrusted data. Successful exploitation by an authenticated attacker with specific privileges, namely "DNA Authority - Operator," could allow them to tamper with serialized data. This tampering, when deserialized, could lead to arbitrary code execution within the context of the Enterprise SCADA security group "DNA Apps."

Multiple versions of AVEVA Enterprise SCADA are confirmed to be affected. This includes Enterprise SCADA 2025, versions ranging from 2024 to 2024 SP1_P01, 2023 to 2023 SP1, 2022 to 2022 SP2_P2, and versions up to 2021 SP2_P5. Additionally, AVEVA Enterprise SCADA HMI versions 2024, 2024 R2, and versions up to 2023 P1 are also impacted.

The Common Vulnerability Scoring System (CVSS) v3.1 base score for CVE-2025-7639 is rated as HIGH at 7.1, with a vector string of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H. This indicates a significant potential for impact, particularly concerning integrity and availability, despite requiring a high level of attack complexity and specific privileges.

AVEVA has provided a set of remediation and mitigation strategies. Customers are strongly advised to upgrade their Servers and Clients to the latest fixed versions. Specific configuration changes are also mandated to fully mitigate the risk. These include altering the "BinarySerializer" mode from 'Binary Formatter' to 'Json' and setting "AcceptBinaryFormattedData" to 'false' on server components. Client components should also be configured to exclusively use JSON serialization.

Further mitigation steps involve migrating HMI displays and applying specific security updates. AVEVA recommends contacting their technical support for the most applicable security update based on the deployed product version. Detailed instructions for these configuration changes and a list of compatible server-client versions can be found in AVEVA's Knowledge Base article KB117814, titled "AVEVA Midstream Product Bulletin - Removal of Binary Formatter."

Beyond immediate patching and configuration, AVEVA suggests general defensive measures. These include auditing devices, network topology, and perimeter defenses according to their Reference System Architecture. Crucially, organizations should audit assigned permissions to ensure only trusted users possess "DNA Authority - Operator" rights and disallow BLT Test clients in production environments.

This vulnerability was reported to CISA by AVEVA, highlighting the ongoing efforts to secure critical infrastructure. CISA encourages organizations to perform thorough impact analyses and risk assessments before implementing any defensive measures, emphasizing best practices for control systems security.

Synthesized by Vypr AI