AVEVA Enterprise SCADA
MonitorCVSS 7.1ICS-CERT ICSA-26-225-01Aug 13, 2026
AVEVAEnergyManufacturing
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
AVEVA Enterprise SCADA contains an unsafe deserialization vulnerability (CWE-502) in the BinarySerializer component. Attackers with valid engineering credentials can craft malicious serialized data that executes arbitrary code when deserialized by the server or HMI client. Affected versions include Enterprise SCADA 2021 through 2025 and Enterprise SCADA HMI 2023 and 2024. The vulnerability stems from use of .NET BinaryFormatter, which is inherently unsafe for untrusted data.
What this means
What could happen
An attacker with engineering workstation credentials could tamper with serialized data sent to AVEVA Enterprise SCADA servers, leading to arbitrary code execution and potential control of industrial processes including shutdowns or unsafe setpoint changes.
Who's at risk
Energy and manufacturing organizations operating AVEVA Enterprise SCADA systems for supervisory control and monitoring, including power generation, distribution, and pipeline operations facilities that rely on HMI clients and server infrastructure.
How it could be exploited
An attacker with valid engineering credentials sends malicious serialized data to the AVEVA server via the network. During deserialization, the malicious payload executes with server privileges, allowing the attacker to run arbitrary commands on the SCADA server or HMI client.
Prerequisites
- Valid engineering workstation credentials
- Network access to AVEVA Enterprise SCADA server on the default communication port
- Server or client running affected version without binary serialization disabled
remotely exploitablerequires valid credentialsaffects safety-critical SCADA systemscode execution possiblelow-complexity attack
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (7)
7 pending
ProductAffected VersionsFix Status
Enterprise SCADA: 20252025No fix yet
Enterprise SCADA: >=2024|<=2024_SP1_P01≥ 2024|≤ 2024 SP1 P01No fix yet
Enterprise SCADA: >=2023|<=2023_SP1≥ 2023|≤ 2023 SP1No fix yet
Enterprise SCADA: >=2022|<=2022_SP2_P2≥ 2022|≤ 2022 SP2 P2No fix yet
Enterprise SCADA≤ 2021 SP2 P5No fix yet
Enterprise SCADA HMI: 2024|2024_R22024|2024|R2No fix yet
Enterprise SCADA HMI≤ 2023 P1No fix yet
Remediation & Mitigation
0/5
Do now
0/1Enterprise SCADA
WORKAROUNDRestrict network access to AVEVA Enterprise SCADA servers to authorized engineering workstations only using firewall rules
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Enterprise SCADA
HOTFIXUpgrade AVEVA Enterprise SCADA servers to v2025 P1, v2024 SP1 P2, v2023 SP1 P1, v2022 SP2 P3, or v2021 SP2 P6 or later
HOTFIXUpgrade AVEVA Enterprise SCADA HMI clients to v2024 R2 HF7, v2024 P1, or v2023 P2 HF1 or later
All products
HARDENINGAfter upgrading all server and client nodes, change the BinarySerializer Mode setting from 'Binary Formatter' to 'Json' on all servers
HARDENINGAfter upgrading all server and client nodes, change the BinarySerializer AcceptBinaryFormattedData setting from 'true' to 'false' on all servers
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/5a179cf3-a219-4245-b5d0-b9583f7b185cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.