GHSA-4m9v-7gg3-m6j6CriticalCVSS 7.1
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority -...
🔗 CVE IDs covered (1)
📋 Description
The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2025-7639
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-01.json
- https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-005.pdf
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01
- https://github.com/advisories/GHSA-4m9v-7gg3-m6j6