Description
The vulnerability, if exploited, could allow an authenticated miscreant
with "DNA Authority - Operator" privilege to tamper with serialized
data, potentially resulting in code execution during deserialization
under the privilege of Enterprise SCADA security group "DNA Apps".
Published: 2026-08-14
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the deserialization of untrusted data using the legacy Binary Formatter in AVEVA Enterprise SCADA components. When an authenticated user with DNA Authority – Operator privileges tamper with serialized objects, the application can deserialize the corrupted data and execute arbitrary code under the privilege of the DNA Apps security group. This flaw allows an attacker to run arbitrary code on the server or client, compromising confidentiality, integrity, and availability of the SCADA system.

Affected Systems

Affected products include AVEVA Enterprise SCADA, AVEVA Enterprise SCADA HMI, AVEVA Pipeline Integrity Monitor, AVEVA Pipeline Operations for Gas/Liquids, AVEVA Pipeline Training Simulator, and Measurement Advisor. The flaw impacts server versions from AVEVA Enterprise SCADA 2021 SP2 P6 through 2025 P1 and newer, and equivalent Pipeline Operations versions, as well as client versions from AVEVA Enterprise SCADA HMI 2023 P2 HF1 through 2024 R2 HF7. Clients and interfaces that rely on binary serialization are also vulnerable until they are upgraded to the security‑patched releases.

Risk and Exploitability

The CVSS score of 10 indicates a maximum severity, and the absence of an EPSS score signifies uncertainty about current exploitation frequency, yet the CVE is not listed in CISA’s KEV catalog. The flaw can be exploited by an authenticated user with sufficient privileges, implying that threat actors who have compromised an account or gained insider access can trigger the vulnerability. Once exploited, the attacker gains the ability to execute arbitrary code within the scope of the SCADA application, potentially leading to system compromise and data tampering.

Generated by OpenCVE AI on August 14, 2026 at 20:53 UTC.

Remediation

Vendor Solution

Security Updates Contact your AVEVA Technical Support representative, Customer Success Manager, Account Manager, or Solution Integrator to obtain the security update best applicable to the product version currently deployed in your environment: Servers: • AVEVA Enterprise SCADA v2025 P1 or higher • AVEVA Enterprise SCADA v2024 SP1 P2 • AVEVA Enterprise SCADA v2023 SP1 P1 • AVEVA Enterprise SCADA v2022 SP2 P3 • AVEVA Enterprise SCADA v2021 SP2 P6 • AVEVA Pipeline Operations for Gas/Liquids v2025 P1 or higher • AVEVA Pipeline Operations for Gas/Liquids v2024 SP1 P2 • AVEVA Pipeline Operations for Gas/Liquids v2023 SP1 P1 • AVEVA Pipeline Operations for Gas/Liquids v2022 SP2 P3 • AVEVA Pipeline Operations for Gas/Liquids v2021 SP2 P6 Clients: • AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher • AVEVA Enterprise SCADA HMI v2024 P1 • AVEVA Enterprise SCADA HMI v2023 P2 HF1 • AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher • AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media) v2025 SP1 P2 or higher • Measurement Advisor 2025 P1 or higher • Measurement Advisor 2021 SP1 HF16


Vendor Workaround

Defensive Measures and General Considerations The following general defensive measures are recommended: - Audit devices, network topology, and perimeter defences to ensure all applicable security best practices from AVEVA’s Enterprise SCADA Reference System Architecture are adhered to. - Audit assigned permissions to ensure that only trusted users are given https://docs.aveva.com/bundle/scada-ent-2025/page/651008.html - Disallow BLT Test clients in production environments. For additional details on defensive measures, please refer to Section 5 of KB117814 “AVEVA Midstream Product Bulletin – Removal of Binary Formatter” https://softwaresupportsp.aveva.com/en-US/knowledge/details/000117814 .


OpenCVE Recommended Actions

  • Upgrade all affected AVEVA Enterprise SCADA, Pipeline Operations, HMI, and other listed products to the latest patched versions as outlined in the AVEVA security bulletin
  • Configure servers to set the BinarySerializer "Mode" to "Json" and change "AcceptBinaryFormattedData" to "false", then re‑cache the XOS Event Handlers assembly
  • Modify all client configurations to enforce JSON serialization only and migrate any HMI displays that use the legacy serializer
  • Audit devices, network topology, and perimeter defences to ensure all applicable security best practices are adhered to
  • Audit assigned permissions to ensure that only trusted users are given the necessary privileges
  • Disallow BLT Test clients in production environments

Generated by OpenCVE AI on August 14, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".
Title AVEVA Enterprise SCADA Deserialization of Untrusted Data
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-14T19:32:00.429Z

Reserved: 2025-07-14T14:27:04.249Z

Link: CVE-2025-7639

cve-icon Vulnrichment

Updated: 2026-08-14T19:31:55.696Z

cve-icon NVD

Status : Received

Published: 2026-08-14T19:17:13.380

Modified: 2026-08-14T20:16:47.673

Link: CVE-2025-7639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:00:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data