news.mlab.sh
Back to the feed
vulnerability

AVEVA Enterprise SCADA

High
Summary

A critical vulnerability (CVE-2025-7639) has been identified in AVEVA Enterprise SCADA, allowing an authenticated attacker with specific privileges to tamper with serialized data and potentially execute code. This vulnerability affects multiple versions of AVEVA Enterprise SCADA and related products, including HMI, and is considered high severity due to its potential for code execution. Mitigation requires upgrading to supported versions and implementing specific configuration changes to disable binary formatting and restrict data serialization.

Read the full article at CISA Advisories

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.