# AVEVA SCADA Deserialization Flaw Enables Code Execution

Published: 2026-08-13 · Severity: routine · Sectors: manufacturing, energy
Canonical: https://vorant.io/reports/65d94470-ffd2-584c-9088-efcfebdfb601/aveva-scada-deserialization-flaw-enables-code-execution

> An authenticated deserialization vulnerability in AVEVA Enterprise SCADA could let a privileged operator achieve code execution, no public exploitation observed.

CISA has published an advisory for AVEVA Enterprise SCADA products affected by CVE-2025-7639, a deserialization of untrusted data vulnerability (CWE-502). An attacker who already holds "DNA Authority - Operator" privileges could tamper with serialized data to trigger code execution during deserialization, running under the elevated privileges of the "DNA Apps" security group. The flaw affects multiple Enterprise SCADA and Enterprise SCADA HMI versions from 2021 through 2025, and by extension AVEVA Pipeline Operations, Pipeline Integrity Monitor, and Measurement Advisor products that share the same binary serialization component.

AVEVA's remediation requires upgrading server and client components to fixed versions and then reconfiguring the BinarySerializer mode from 'Binary Formatter' to 'Json', disabling AcceptBinaryFormattedData, and migrating HMI displays — a multi-step process detailed in vendor KB117814. CISA notes the vulnerability has high attack complexity and no known public exploitation has been reported. The advisory is primarily relevant to Critical Manufacturing and broader industrial/pipeline operators using AVEVA SCADA deployed worldwide, and organizations should prioritize auditing operator privilege assignments and disallowing BLT test clients in production alongside the patching timeline.

## Mentioned in this report

- Vulnerabilities: CVE-2025-7639

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/65d94470-ffd2-584c-9088-efcfebdfb601/aveva-scada-deserialization-flaw-enables-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
