AVEVA
AVEVA Enterprise SCADA
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2025-7639 | 14 Aug 2026 | AVEVA Enterprise SCADA: 2025, 2024 ≤ 2024 SP1 P01, 2023 ≤ 2023 SP1, 2022 ≤ 2022 SP2 P2, ≤ 2021 SP2 P5; AVEVA Enterprise SCADA HMI: 2024, ≤ 2023_P1, 2024 R2 | AVEVA Enterprise SCADA: 2025 P1, 2024 SP1 P2, 2023 SP1 P1, 2022 SP2 P3, 2021 SP2 P6; AVEVA Enterprise SCADA HMI: 2024 R2 HF7, 2024 P1, 2023 P2 HF1; AVEVA Pipeline Operations for Gas/Liquids: 2025 P1, 2024 SP1 P2, 2023 SP1 P1, 2022 SP2 P3, 2021 SP2 P6; AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media): 2025 SP1 P2; AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media): 2025 SP1 P2; Measurement Advisor: 2025 P1, 2021 SP1 HF16 | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.