Upgrade affected servers to AVEVA Enterprise SCADA v2025 P1 or higher, v2024 SP1 P2, v2023 SP1 P1, v2022 SP2 P3, or v2021 SP2 P6. Upgrade clients to AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher, v2024 P1, or v2023 P2 HF1. After upgrading, configure Server Components: change "BinarySerializer" -> "Mode" from 'Binary Formatter' to 'Json' and set "AcceptBinaryFormattedData" from 'true' to 'false', then re-cache the XOS Event Handlers assembly. Configure Client Components to use JSON serialization only. Refer to AVEVA KB117814 for step-by-step instructions.
Quick answers
What is CVE-2025-7639?
Upgrade affected servers to AVEVA Enterprise SCADA v2025 P1 or higher, v2024 SP1 P2, v2023 SP1 P1, v2022 SP2 P3, or v2021 SP2 P6. Upgrade clients to AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher, v2024 P1, or v2023 P2 HF1. After upgrading, configure Server Components: change "BinarySerializer" -> "Mode" from 'Binary Formatter' to 'Json' and set "AcceptBinaryFormattedData" from 'true' to 'false', then re-cache the XOS Event Handlers assembly. Configure Client Components to use JSON serialization only. Refer to AVEVA KB117814 for step-by-step instructions.
How severe is CVE-2025-7639?
high, CVSS 7.1
Is CVE-2025-7639 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2025-7639 be mitigated?
Upgrade affected servers to AVEVA Enterprise SCADA v2025 P1 or higher, v2024 SP1 P2, v2023 SP1 P1, v2022 SP2 P3, or v2021 SP2 P6. Upgrade clients to AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher, v2024 P1, or v2023 P2 HF1. After upgrading, configure Server Components: change "BinarySerializer" -> "Mode" from 'Binary Formatter' to 'Json' and set "AcceptBinaryFormattedData" from 'true' to 'false', then re-cache the XOS Event Handlers assembly. Configure Client Components to use JSON serialization only. Refer to AVEVA KB117814 for step-by-step instructions.
CVSS
7.1
Vendor
AVEVA
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
AVEVA Enterprise SCADA 2025, AVEVA Enterprise SCADA >=2024|<=2024_SP1_P01, AVEVA Enterprise SCADA >=2023|<=2023_SP1, AVEVA Enterprise SCADA >=2022|<=2022_SP2_P2, AVEVA Enterprise SCADA <=2021_SP2_P5, AVEVA Enterprise SCADA HMI 2024|2024_R2, AVEVA Enterprise SCADA HMI <=2023_P1
Mitigation
Upgrade affected servers to AVEVA Enterprise SCADA v2025 P1 or higher, v2024 SP1 P2, v2023 SP1 P1, v2022 SP2 P3, or v2021 SP2 P6. Upgrade clients to AVEVA Enterprise SCADA HMI v2024 R2 HF7 or higher, v2024 P1, or v2023 P2 HF1. After upgrading, configure Server Components: change "BinarySerializer" -> "Mode" from 'Binary Formatter' to 'Json' and set "AcceptBinaryFormattedData" from 'true' to 'false', then re-cache the XOS Event Handlers assembly. Configure Client Components to use JSON serialization only. Refer to AVEVA KB117814 for step-by-step instructions.
A deserialization of untrusted data vulnerability (CVE-2025-7639) in AVEVA Enterprise SCADA has been assigned a CVSS v3 score of 7.1. The flaw affects multiple product releases spanning 2021 through 2025, including Enterprise SCADA and HMI editions. Exploitation requires authenticated access with "DNA Authority - Operator" privilege and could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization under the "DNA Apps" security group privileges. AVEVA has released mitigation guidance and fixed versions to address the issue.