THE ICS Advisory ICSA-26-225-01 addresses a critical vulnerability in AVEVA Enterprise SCADA that could allow attackers to tamper with serialized data, potentially resulting in code execution during deserialization. Affected versions include several releases from 2021 to 2025. The CVSS score for the vulnerability is 7.1, indicating a high severity.
Mitigation recommendations include upgrading to fixed versions, changing configuration settings to use JSON instead of binary serialization, and auditing permissions related to 'DNA Authority - Operator' rights. CISA emphasizes the importance of performing risk assessments and implementing cybersecurity best practices to protect against exploitation.