AVEVA Enterprise SCADA

Summary

A deserialization of untrusted data vulnerability, identified as CVE-2025-7639, has been found in multiple versions of AVEVA Enterprise SCADA. Successful exploitation by an authenticated attacker could allow for tampering with serialized data, potentially leading to code execution with elevated privileges.

IFF Assessment

FOE

The identified vulnerability allows for code execution, which is a significant risk to defenders and could be exploited by attackers.

Severity

7.1 High

Defender Context

This vulnerability in AVEVA Enterprise SCADA, a product used in critical manufacturing, poses a significant risk due to its potential for code execution. Defenders should prioritize patching or applying mitigations for affected versions and monitor for any indicators of compromise related to data tampering or unauthorized code execution within their SCADA environments.

Read Full Story →