在 openPDC 和 openHistorian 中,服务控制台接口会反序列化由客户端提供的数据结构。在使用 Windows 身份验证的系统上,攻击者必须已通过身份认证才能访问此功能;而在未启用 Windows 身份验证的系统上,未经身份验证的远程网络攻击者也可直接访问该功能。这使攻击者能够触发任意对象图的反序列化,从而可能导致以受影响服务账户的权限执行远程代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grid Protection Alliance | openHistorian | < 2.8.580 |
affected |
< 2.8.585 |
affected | ||
2.8.585 |
unaffected | ||
| Grid Protection Alliance | openPDC | < 2.9.477 |
affected |
< 2.9.482 |
affected | ||
2.9.482 |
unaffected | ||
| Grid Protection Alliance | openPDC (Docker image) | < 2.9.477 |
affected |
< 2.9.482 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grid Protection Alliance | openPDC | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openPDC (Docker image) | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openHistorian | 0 ~ 2.8.580 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105278 | 9.8 CRITICAL | Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials |
| CVE-2026-104629 | 8.8 HIGH | Grid Protection Alliance openPDC and openHistorian Use of Externally-Controlled Input to S |
| CVE-2026-105281 | 7.5 HIGH | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-85479 | 5.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-101022 | 4.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF) |
No comments yet