What is CVE-2025-7639?
CVE-2025-7639 allows an authenticated attacker with 'DNA Authority - Operator' privileges to tamper with serialized data, potentially leading to code execution during deserialization under the 'DNA Apps' Enterprise SCADA security group. This poses a critical risk to SCADA environments, requiring immediate review of access controls and patch application.
Azərbaycanca: CVE-2025-7639 "DNA Authority - Operator" imtiyazlı autentifikasiya olunmuş hücumçuya seriallaşdırılmış məlumatları manipulyasiya etməyə imkan verir, bu da deserializasiya zamanı "DNA Apps" SCADA təhlükəsizlik qrupu imtiyazı ilə kod icrasına səbəb ola bilər. Bu, xüsusilə SCADA mühitlərində ciddi təhlükə yaradır; operativ olaraq müvafiq giriş nəzarətləri yoxlanmalı və yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
What privileges does an attacker need to exploit CVE-2025-7639?
This vulnerability can be exploited by an authenticated attacker with 'DNA Authority - Operator' privileges.
Under which security group context can successful exploitation of CVE-2025-7639 lead to code execution?
Successful exploitation can lead to code execution under the 'DNA Apps' Enterprise SCADA security group.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.