Junglewise Threat Intelligence

CVE-2025-7639: AVEVA DNA deserialization code execution

CVE-2025-7639 · Severity: high · CVSS 7.1 · Published 2026-08-14

Executive brief

AVEVA DNA is an industrial control system platform used to manage enterprise-scale SCADA environments and manufacturing operations. A flaw in serialized data handling allows authenticated operators with specific privileges to inject malicious code that executes with elevated system permissions, potentially compromising critical industrial infrastructure.

Technical details

This is a deserialization vulnerability in AVEVA DNA that allows an authenticated user with "DNA Authority - Operator" privilege to tamper with serialized data structures. When the malicious payload is deserialized, it results in arbitrary code execution under the privilege context of the Enterprise SCADA security group "DNA Apps". The vulnerability requires authentication and a specific privilege level, limiting the attack surface to insider threats or compromised operator accounts. Exploitation allows an attacker to execute arbitrary code with the privileges of the DNA Apps security group, potentially leading to control of SCADA systems and critical industrial processes.

Affected products

  • AVEVA DNA <UNKNOWN>

Timeline

  • 2026-08-14: disclosed

References