Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-7639— AVEVA Enterprise SCADA Deserialization of Untrusted Data

Quick assessment

Affected
AVEVA AVEVA Enterprise SCADA
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AVEVA Enterprise SCADA是英国AVEVA公司的一款工业监控与数据采集系统。 AVEVA Enterprise SCADA 2025版本、2024 SP1 P01及之前版本、2023 SP1及之前版本、2022 SP2 P2及之前版本和2021 SP2 P5及之前版本存在反序列化注入漏洞,该漏洞源于序列化数据被篡改,具有DNA Authority - Operator权限的已认证攻击者可能利用此漏洞在Enterprise SCADA安全组DNA Apps权限下执行代码。

CVSS 7.1 · High EPSS 0.57% · P45

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 25

VendorProduct Version RangeStatus
AVEVA AVEVA Enterprise SCADA 2025 affected
2024≤ 2024 SP1 P01 affected
2023≤ 2023 SP1 affected
2022≤ 2022 SP2 P2 affected
≤ 2021 SP2 P5 affected
2025 P1 unaffected
2024 SP1 P2 unaffected
2023 SP1 P1 unaffected
… +2 more rows
AVEVA AVEVA Enterprise SCADA HMI 2024 affected
≤ 2023_P1 affected
2024 R2 affected
2024 R2 HF7 unaffected
2024 P1 unaffected
2023 P2 HF1 unaffected
AVEVA AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media) 2025 SP1 P2 unaffected
AVEVA AVEVA Pipeline Operations for Gas/Liquids 2025 P1 unaffected
2024 SP1 P2 unaffected
2023 SP1 P1 unaffected
2022 SP2 P3 unaffected
2021 SP2 P6 unaffected
AVEVA AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media) 2025 SP1 P2 unaffected
AVEVA Measurement Advisor 2025 P1 unaffected
2021 SP1 HF16 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-7639

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AVEVA Enterprise SCADA Deserialization of Untrusted Data
Source: CVE Program / CVE List V5
Vulnerability Description
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
AVEVA Enterprise SCADA 反序列化注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
AVEVA Enterprise SCADA是英国AVEVA公司的一款工业监控与数据采集系统。 AVEVA Enterprise SCADA 2025版本、2024 SP1 P01及之前版本、2023 SP1及之前版本、2022 SP2 P2及之前版本和2021 SP2 P5及之前版本存在反序列化注入漏洞,该漏洞源于序列化数据被篡改,具有DNA Authority - Operator权限的已认证攻击者可能利用此漏洞在Enterprise SCADA安全组DNA Apps权限下执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

II. Public POCs for CVE-2025-7639

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-7639

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-7639 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2025-7639

No comments yet


Leave a comment