<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Measurement Advisor - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/measurement-advisor/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:53:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/measurement-advisor/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>AVEVA Enterprise SCADA Deserialization Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-08-aveva-scada-deserialization/</link><pubDate>Thu, 13 Aug 2026 16:53:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-aveva-scada-deserialization/</guid><description>Authenticated attackers with operator-level access can exploit a deserialization vulnerability (CVE-2025-7639) in AVEVA Enterprise SCADA to achieve remote code execution.</description><content:encoded><![CDATA[<p>AVEVA has identified a high-severity deserialization vulnerability, tracked as CVE-2025-7639, affecting multiple versions of the AVEVA Enterprise SCADA suite. The vulnerability exists within the application's handling of serialized data, specifically when using the 'Binary Formatter' mode. An authenticated attacker possessing 'DNA Authority - Operator' privileges can manipulate serialized data streams to force the application to execute arbitrary code under the security context of the 'DNA Apps' service group.</p>
<p>This issue impacts a wide range of versions, including the 2025 release and various service packs of the 2021 through 2024 versions. Because this affects critical infrastructure sectors and involves code execution, it poses a significant risk to industrial operations. AVEVA has released security updates and recommended configuration changes, including the migration from Binary Formatter to JSON serialization, to remediate the vulnerability.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to achieve remote code execution within the 'DNA Apps' security group context. This could lead to full control over affected SCADA servers and HMI clients, potentially enabling unauthorized process control or disruption of critical manufacturing operations globally.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all affected Server and Client nodes to the versions specified in AVEVA Security Bulletin AVEVA-2026-005.</li>
<li>Implement the recommended configuration changes by updating 'BinarySerializer' mode settings from 'Binary Formatter' to 'JSON' and disabling 'AcceptBinaryFormattedData'.</li>
<li>Audit assigned permissions to ensure that only authorized personnel maintain 'DNA Authority - Operator' privileges.</li>
<li>Disable any 'BLT Test' clients currently running within production environments as per vendor guidance.</li>
<li>Review KB117814 for detailed step-by-step instructions on migration and configuration hardening.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ics</category><category>scada</category><category>deserialization</category><category>cve-2025-7639</category></item></channel></rss>