Impact
The vulnerability arises from the deserialization of untrusted data using the legacy Binary Formatter in AVEVA Enterprise SCADA components. When an authenticated user with DNA Authority – Operator privileges tamper with serialized objects, the application can deserialize the corrupted data and execute arbitrary code under the privilege of the DNA Apps security group. This flaw allows an attacker to run arbitrary code on the server or client, compromising confidentiality, integrity, and availability of the SCADA system.
Affected Systems
Affected products include AVEVA Enterprise SCADA, AVEVA Enterprise SCADA HMI, AVEVA Pipeline Integrity Monitor, AVEVA Pipeline Operations for Gas/Liquids, AVEVA Pipeline Training Simulator, and Measurement Advisor. The flaw impacts server versions from AVEVA Enterprise SCADA 2021 SP2 P6 through 2025 P1 and newer, and equivalent Pipeline Operations versions, as well as client versions from AVEVA Enterprise SCADA HMI 2023 P2 HF1 through 2024 R2 HF7. Clients and interfaces that rely on binary serialization are also vulnerable until they are upgraded to the security‑patched releases.
Risk and Exploitability
The CVSS score of 10 indicates a maximum severity, and the absence of an EPSS score signifies uncertainty about current exploitation frequency, yet the CVE is not listed in CISA’s KEV catalog. The flaw can be exploited by an authenticated user with sufficient privileges, implying that threat actors who have compromised an account or gained insider access can trigger the vulnerability. Once exploited, the attacker gains the ability to execute arbitrary code within the scope of the SCADA application, potentially leading to system compromise and data tampering.
OpenCVE Enrichment