[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQy8VSX1uk7ITED2COkKYmro6wO0P6pwdv49OtV5qFpI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"056d59c4-e0c7-4365-961d-bed33a87e0dc","critical-deserialization-flaw-in-aveva-scada-threatens-industrial-control-systems","9bf8d1c2-a110-4d77-806b-3a9b94bb6346","Critical Deserialization Flaw in AVEVA SCADA Threatens Industrial Control Systems","A critical deserialization vulnerability (CVE-2025-7639) in AVEVA Enterprise SCADA exposes industrial control systems to data tampering and remote code execution across versions 2022–2025. The root cause lies in the use of an insecure serialization format — Binary Formatter — which is well-known to be exploitable during object deserialization. This is particularly dangerous in operational technology (OT) environments where system integrity and availability are directly tied to physical processes. The fact that mitigation requires a configuration change rather than just a patch highlights how insecure defaults in industrial software can create long-standing risk. Leaving such settings unchecked in critical infrastructure environments can have cascading consequences well beyond data loss.","**Immediate actions:**\n- Reconfigure all affected AVEVA SCADA instances from 'Binary Formatter' to 'Json' serialization as directed in the vendor advisory.\n- Update all client components and HMI displays to the latest supported versions to close the attack surface.\n- Audit all SCADA systems for exposure to untrusted networks and apply emergency isolation if exploitation risk is high.\n\n**Long-term improvements:**\n- Establish a secure baseline configuration standard for all OT\u002FSCADA software that explicitly prohibits insecure serialization formats.\n- Integrate ICS\u002FSCADA software into your vulnerability management program with defined SLAs for critical CVEs.\n- Maintain a complete and current inventory of all industrial control system components, versions, and configurations.\n\n**Detection measures:**\n- Deploy OT-aware intrusion detection systems (IDS) capable of identifying anomalous deserialization activity on SCADA networks.\n- Enable detailed logging on SCADA servers and forward logs to a SIEM for continuous monitoring and alerting.\n- Conduct periodic configuration audits against vendor hardening guides to detect configuration drift early.",[12,13,14,15,16,17,18,19,20],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 7 – Continuous Vulnerability Management","NIST SP 800-82 – Guide to ICS Security","NIST SI-10 – Information Input Validation","NIST CM-6 – Configuration Settings","NIST RA-5 – Vulnerability Scanning","IEC 62443-3-3 – System Security Requirements and Security Levels","NERC CIP-007-6 – Systems Security Management","ITIL – Change and Release Management","published","2026-08-13T19:22:08.29832+00:00","2026-08-13T19:22:08.007+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-225-01","aveva-enterprise-scada-0da9a6","AVEVA Enterprise SCADA",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]