AVEVA Enterprise SCADA
Brief
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA =2024
- =2023
- =2022
- =2024
- =2023
- =2022
- "Mode" setting from 'Binary Formatter' to 'Json'. Change "BinarySerializer" - "AcceptBinaryFormattedData" setting from 'true' to 'false'. Re-cache the XOS Event Handlers assembly
Mitigation
Client Components: Configure clients/products that interface with Enterprise SCADA to only use JSON serialization.
