{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/enterprise-scada-2021/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Enterprise SCADA 2025","Enterprise SCADA 2024","Enterprise SCADA 2023","Enterprise SCADA 2022","Enterprise SCADA 2021","Enterprise SCADA HMI","Pipeline Operations for Gas/Liquids","Pipeline Integrity Monitor","Pipeline Training Simulator","Measurement Advisor"],"_cs_severities":["high"],"_cs_tags":["ics","scada","deserialization","cve-2025-7639"],"_cs_type":"advisory","_cs_vendors":["AVEVA"],"content_html":"\u003cp\u003eAVEVA has identified a high-severity deserialization vulnerability, tracked as CVE-2025-7639, affecting multiple versions of the AVEVA Enterprise SCADA suite. The vulnerability exists within the application's handling of serialized data, specifically when using the 'Binary Formatter' mode. An authenticated attacker possessing 'DNA Authority - Operator' privileges can manipulate serialized data streams to force the application to execute arbitrary code under the security context of the 'DNA Apps' service group.\u003c/p\u003e\n\u003cp\u003eThis issue impacts a wide range of versions, including the 2025 release and various service packs of the 2021 through 2024 versions. Because this affects critical infrastructure sectors and involves code execution, it poses a significant risk to industrial operations. AVEVA has released security updates and recommended configuration changes, including the migration from Binary Formatter to JSON serialization, to remediate the vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to achieve remote code execution within the 'DNA Apps' security group context. This could lead to full control over affected SCADA servers and HMI clients, potentially enabling unauthorized process control or disruption of critical manufacturing operations globally.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all affected Server and Client nodes to the versions specified in AVEVA Security Bulletin AVEVA-2026-005.\u003c/li\u003e\n\u003cli\u003eImplement the recommended configuration changes by updating 'BinarySerializer' mode settings from 'Binary Formatter' to 'JSON' and disabling 'AcceptBinaryFormattedData'.\u003c/li\u003e\n\u003cli\u003eAudit assigned permissions to ensure that only authorized personnel maintain 'DNA Authority - Operator' privileges.\u003c/li\u003e\n\u003cli\u003eDisable any 'BLT Test' clients currently running within production environments as per vendor guidance.\u003c/li\u003e\n\u003cli\u003eReview KB117814 for detailed step-by-step instructions on migration and configuration hardening.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:53:25Z","date_published":"2026-08-13T16:53:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-aveva-scada-deserialization/","summary":"Authenticated attackers with operator-level access can exploit a deserialization vulnerability (CVE-2025-7639) in AVEVA Enterprise SCADA to achieve remote code execution.","title":"AVEVA Enterprise SCADA Deserialization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-aveva-scada-deserialization/"}],"language":"en","title":"CraftedSignal Threat Feed - Enterprise SCADA 2021","version":"https://jsonfeed.org/version/1.1"}