CVE-2025-7639: Aveva Enterprise Scada

High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".

Affected products

  • Aveva Aveva Enterprise Scada: version 2025 only; from 2024, up to and including 2024 SP1 P01; from 2023, up to and including 2023 SP1; from 2022, up to and including 2022 SP2 P2; up to and including 2021 SP2 P5
  • Aveva Aveva Enterprise Scada HMI: version 2024 only; up to and including 2023_P1; version 2024 R2 only
  • Aveva Aveva Pipeline Integrity Monitor Delivered On Pipeline Simulation Media
  • Aveva Aveva Pipeline Operations For Gas/liquids
  • Aveva Aveva Pipeline Training Simulator Delivered On Pipeline Simulation Media
  • Aveva Measurement Advisor

Published 2026-08-14. Last modified 2026-09-29.